boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-404

Weakness type CWE-404 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
68661

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆▅█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 18 · 2026-06 15 · 2026-07 24 · 2026-08 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-81207.099.4KEVMicrosoft Win32k
CVE-2025-156872.146.6Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
CVE-2025-156862.141.4Open5GS HSS Service fd_msg_sess_get denial of service
CVE-2026-386417.537.3
CVE-2026-100698.736.7Shibby Tomato miniupnpd resource consumption
CVE-2026-106505.535.9warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
CVE-2026-95405.535.8vllm-project vllm OpenAI-compatible Serving Path denial of service
CVE-2026-175006.935.1ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference
CVE-2026-175016.935.1ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform …
CVE-2026-134912.934.578 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
CVE-2026-101162.132.4Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service
CVE-2026-102245.530.5NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource c…
CVE-2026-193625.530.5lmammino oidc-authorizer Authorization Header Parsing parse_token_from_header.rs parse_…
CVE-2026-101905.730.0Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
CVE-2026-750125.729.2TOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null pointer derefer…
CVE-2026-750135.729.2TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference
CVE-2026-597257.528.6Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-606246.528.3
CVE-2026-197452.127.7Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
CVE-2026-197462.127.7Calix GigaSpire traceroute.cmd denial of service

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle5
ggml-org3
gnu3
calix2
connorskees2
linux2
nousresearch2
omec-project2
totolink2
781
aio-libs1
almico1
boxlite-ai1
bytedance1
cyberark software, a palo alto networks company1