boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-401

Weakness type CWE-401 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2691750

Monthly trend

▂▁▃▁▂▁▁▁▁▂▂▂▁▂▁▁▂▁▂▃▁▁▁▁▁▁██▇▂

2025-09 6 · 2025-10 12 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 2 · 2026-04 1 · 2026-05 56 · 2026-06 56 · 2026-07 49 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-36535.377.6Undertow: learningpushhandler can lead to remote memory dos attacks
CVE-2024-10236.574.6Io.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structure…
CVE-2024-13947.572.8Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads
CVE-2026-354247.565.4Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2024-273885.558.7SUNRPC: fix some memleaks in gssx_dec_option_array
CVE-2026-448067.554.3Windows Secure Channel Denial of Service Vulnerability
CVE-2024-273937.552.8xen-netfront: Add missing skb_mark_for_recycle
CVE-2026-480068.751.8Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2024-421524.751.5nvmet: fix a possible leak when destroy a ctrl during qp establishment
CVE-2023-526105.547.9net/sched: act_ct: fix skb leak and crash on ooo frags
CVE-2026-581758.247.7Apache Traffic Server: HostDB SRV handling leaks memory
CVE-2026-480598.747.5Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M…
CVE-2026-16057.547.3
CVE-2026-480437.546.9netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener …
CVE-2024-369115.546.6hv_netvsc: Don't free decrypted memory
CVE-2024-385395.546.5RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw
CVE-2024-358825.545.9SUNRPC: Fix a slow server-side memory leak with RPC-over-TCP
CVE-2024-270665.545.7virtio: packed: fix unmap leak for indirect desc table
CVE-2025-464206.544.2Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c
CVE-2024-531784.743.1smb: Don't leak cfid when reconnect races with open_cached_dir

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux200
imagemagick18
netty5
red hat5
eclipse foundation3
gtermars2
microsoft2
offis dicom2
openvpn2
zephyrproject2
almico1
amazon1
apache1
canonical1
generalsandman1