boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-359

Weakness type CWE-359 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43400

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▂▂▁▁▂▆▄▄█▁

2025-11 1 · 2025-12 1 · 2026-01 1 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 10 · 2026-07 6 · 2026-08 6 · 2026-09 13 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-261928.273.5—Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-208344.653.4—Windows Spoofing Vulnerability
CVE-2026-561717.549.8—Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2019-257628.749.7—Joomla! Component JoomProject 1.1.3.2 Information Disclosure
CVE-2026-480487.549.4—XWiki Platform's Livetable results still allow reconstructing password hashes using 768…
CVE-2026-561248.748.7—phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVE-2026-623288.748.1—9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVE-2020-371738.746.9—AVideo Platform 8.1 - Information Disclosure (User Enumeration)
CVE-2026-256996.145.4—Apache Answer: Authorization Bypass in Timeline API
CVE-2026-582967.143.6—Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-582977.143.5—Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2025-434967.539.9——
CVE-2026-01023.139.3—Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
CVE-2026-262376.639.2—QuMagie
CVE-2026-693515.539.1—Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
CVE-2026-730085.539.1—Windows Biometric Service Information Disclosure Vulnerability
CVE-2026-925656.937.8—Rallly before 4.15.0 Information Disclosure via polls.get
CVE-2026-749667.535.9—Information disclosure in the Form Autofill component
CVE-2026-579608.335.0—Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
CVE-2026-869047.534.9——

Most-affected vendors