boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-377

Weakness type CWE-377 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
20200

Monthly trend

▆▃█▃▂

2026-06 6 · 2026-07 2 · 2026-08 9 · 2026-09 2 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-448787.246.8—Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2026-491347.539.0—CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File
CVE-2026-545845.338.1—mport trusts environment-controlled temporary directories in privileged metadata extrac…
CVE-2025-146025.338.1—Weak File Name Generation in vsDesk
CVE-2026-406355.430.8——
CVE-2026-759206.027.3—phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP
CVE-2026-478527.526.0—Predictable cache directory location allows local ONNX model substitution in Spring AI
CVE-2026-537592.07.9—linuxfabrik-lib: Insecure creation of SQLite databases
CVE-2026-491357.25.5—CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
CVE-2026-453846.15.5—bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Arch…
CVE-2026-634047.34.4—Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (networ…
CVE-2026-464064.43.9—Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and S…
CVE-2026-735856.33.1—Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registrat…
CVE-2026-419912.02.9—Predictable Temporary File in GNU gzip
CVE-2026-622945.12.7—Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
CVE-2026-550864.22.7—Etherpad: Import/export use Math.random() for temp file paths; predictable paths on sha…
CVE-2026-410015.32.3—Predictable Temp Directory in Artemis Auto-configuration
CVE-2026-735846.32.0—Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure t…
CVE-2026-167911.02.0—Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
CVE-2026-798997.90.1—Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability

Most-affected vendors