boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-405

Weakness type CWE-405 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

▃█▁█

2026-05 1 · 2026-06 3 · 2026-07 0 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477747.559.0Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK am…
CVE-2026-729147.537.9Mastodon: Exhausting data by an unauthenticated request to the admin retention API
CVE-2026-542247.119.7Denial of Service in UBB.threads
CVE-2025-323945.316.2AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
CVE-2026-85946.29.9Text::LineFold versions through 2019.001 for Perl duplicate the output based on the num…
CVE-2026-239305.36.9Frontend DoS via the popup.testtriggerexpr action
CVE-2026-239345.16.6Frontend DoS via the validate.api.exists action

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
zabbix2
envoyproxy1
mastodon1
nezumi1
significant-gravitas1
ubb systems1