boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-404

Weakness type CWE-404 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1421355

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▃▄▄█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 18 · 2026-06 15 · 2026-07 24 · 2026-08 21 · 2026-09 56 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-81207.099.5KEVMicrosoft Win32k
CVE-2018-86398.497.6KEVMicrosoft Windows
CVE-2018-86117.890.6KEVMicrosoft Windows
CVE-2018-84057.888.6KEVMicrosoft DirectX Graphics Kernel (DXGKRNL)
CVE-2018-84067.888.6KEVMicrosoft DirectX Graphics Kernel (DXGKRNL)
CVE-2025-97847.582.9—Undertow: undertow madeyoureset http/2 ddos vulnerability
CVE-2026-826695.553.0—klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service
CVE-2026-175006.952.4—ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference
CVE-2026-175016.952.4—ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform …
CVE-2026-781486.952.4—ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference
CVE-2026-95405.552.4—vllm-project vllm OpenAI-compatible Serving Path denial of service
CVE-2026-907845.552.4—Dvidelabs flatcc semantics.c fb_clear_parser memory leak
CVE-2026-918555.552.4—Open5GS PFCP Message handler.c denial of service
CVE-2026-418699.152.3—Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nut…
CVE-2026-922206.951.6—vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_rele…
CVE-2026-828035.551.6—armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null poi…
CVE-2026-848565.551.6—rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service
CVE-2026-863195.551.6—java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource cons…
CVE-2026-865115.551.6—java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource c…
CVE-2026-905825.551.6—evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption

Most-affected vendors