boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-377

Weakness type CWE-377 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

█▃▇

2026-06 6 · 2026-07 2 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-448787.234.6Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2026-491347.519.2CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File
CVE-2026-537592.08.3linuxfabrik-lib: Insecure creation of SQLite databases
CVE-2026-491357.23.0CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
CVE-2026-453846.12.6bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Arch…
CVE-2026-464064.42.0Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and S…
CVE-2026-419912.02.0Predictable Temporary File in GNU gzip
CVE-2026-735856.31.1Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registrat…
CVE-2026-622945.11.0Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
CVE-2026-410015.30.7Predictable Temp Directory in Artemis Auto-configuration
CVE-2026-735846.30.6Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure t…
CVE-2026-167911.00.4Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
CVE-2026-759206.0phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat2
steipete2
anthropics1
flameshot-org1
gnu1
hewlett packard enterprise (hpe)1
lenovo1
linuxfabrik1
rikyoz1
spring1
thorsten1