boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-36

Weakness type CWE-36 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
20191

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▆▃▇█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-202507.899.9KEVRARLAB WinRAR
CVE-2026-492907.654.8Slopsmith has path traversal in archive extractors that allows arbitrary file write → p…
CVE-2026-208344.651.8Windows Spoofing Vulnerability
CVE-2026-321754.350.8.NET Core Tampering Vulnerability
CVE-2026-100448.246.1ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/
CVE-2026-153025.342.7ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
CVE-2026-329978.641.6
CVE-2026-618917.537.7
CVE-2026-5721110.035.9RabbitMQ: UNC SSRF affecting the management UI on Windows
CVE-2026-476066.534.2
CVE-2026-100756.932.0Interinfo|DreamMaker - Path Traversal
CVE-2026-131897.529.3SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET …
CVE-2026-263378.829.0Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and …
CVE-2026-133465.627.9pip absolute path traversal during download from malicious package indexes
CVE-2026-583005.526.8Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-536986.525.7
CVE-2026-542028.523.0TeamDavid: Path Traversal in the archive creation functionality
CVE-2026-472439.28.0Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
CVE-2026-463458.45.5compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
CVE-2026-476305.53.9

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
nvidia2
byrongamatos1
check point1
eclipse foundation1
hyland1
interinfo1
kata-containers1
oscal-compass1
progress1
python packaging authority1
rabbitmq1
reputeinfosystems1
silverpeas1
tobit laboratories1