boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-401

Weakness type CWE-401 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
3402391

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▂▁▂▁▂▁▁▁▁▂▃▁▁▁▁▁▁███▃▆▁

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 4 · 2026-04 1 · 2026-05 58 · 2026-06 56 · 2026-07 56 · 2026-08 17 · 2026-09 41 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-260833.367.6KEVArm Mali Graphics Processing Unit (GPU)
CVE-2024-36535.378.6—Undertow: learningpushhandler can lead to remote memory dos attacks
CVE-2024-10236.575.7—Io.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structure…
CVE-2024-13947.573.9—Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads
CVE-2026-31047.566.4—Memory leak in code preparing DNSSEC proofs of non-existence
CVE-2026-354247.566.4—Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2026-448067.566.4—Windows Secure Channel Denial of Service Vulnerability
CVE-2026-695887.566.4—Windows TCP/IP Denial of Service Vulnerability
CVE-2026-698097.566.4—Windows Active Directory Domain Services Denial of Service Vulnerability
CVE-2026-700657.566.4—Windows DHCP Server Denial of Service Vulnerability
CVE-2026-694976.565.4—Windows DHCP Server Denial of Service Vulnerability
CVE-2024-273885.560.2—SUNRPC: fix some memleaks in gssx_dec_option_array
CVE-2026-480598.757.7—Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M…
CVE-2026-480437.557.7—netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener …
CVE-2026-480068.756.7—Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2024-273937.554.1—xen-netfront: Add missing skb_mark_for_recycle
CVE-2026-692087.553.9—Http4s: DigestAuth nonce map grows unbounded
CVE-2026-934368.753.5—vLLM through 0.29.0 Memory Exhaustion via Rejected Requests
CVE-2026-129327.153.3——
CVE-2024-421524.752.8—nvmet: fix a possible leak when destroy a ctrl during qp establishment

Most-affected vendors