boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-35

Weakness type CWE-35 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
29281

Monthly trend

▂▁▁▁▁▂▁▁▁▄▇▄█▇▃

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 6 · 2026-07 3 · 2026-08 7 · 2026-09 6 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-80888.499.8KEVPath traversal vulnerability in WinRAR
CVE-2025-684289.281.7—jsPDF has Local File Inclusion/Path Traversal vulnerability
CVE-2026-456619.963.0—Dokploy: Remote Code Execution through Path Traversal
CVE-2026-454958.862.7—Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-591159.962.3—Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
CVE-2026-137169.155.1—Path Traversal: '.../...//' in Crafty Controller
CVE-2026-275577.551.8—Path Traversal in /index.php/view_uploaded_iodd_file
CVE-2026-401289.048.2—Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
CVE-2026-691098.748.0——
CVE-2026-426618.843.9—WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability
CVE-2026-527078.142.5—WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability
CVE-2026-491127.540.9—WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability
CVE-2026-527039.640.6—WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability
CVE-2026-497796.536.3—WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability
CVE-2026-853106.536.3—WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability
CVE-2025-591814.835.2—Path traversal Vulnerability
CVE-2026-281577.532.8—WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
CVE-2026-666956.532.6—WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE-2026-828249.329.7—Path traversal may allow arbitrary files to be viewed, created, modified, or deleted
CVE-2026-210928.822.2——

Most-affected vendors