boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-378

Weakness type CWE-378 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
540

Monthly trend

▃▁▁▁▁▁▁▁▁▁▃▁█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 1 · 2026-08 0 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-49537.449.0—Podman: build context bind mount
CVE-2026-463884.42.0—osquery: Unprivileged users can temporarily read file carve contents
CVE-2026-970253.21.9—Flatpak: flatpak: world-readable oci authentication token in system-helper cache path
CVE-2026-970263.91.1—Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path
CVE-2026-252658.80.1—Creation of Temporary File with Insecure Permissions in Qualcomm Software Center

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat3
osquery1
qualcomm1