boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-405

Weakness type CWE-405 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
18180

Monthly trend

▂▅▁▆█▆

2026-05 1 · 2026-06 3 · 2026-07 0 · 2026-08 4 · 2026-09 6 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477747.563.1—Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK am…
CVE-2026-729147.556.0—Mastodon: Exhausting data by an unauthenticated request to the admin retention API
CVE-2026-750295.352.1—Message parser retains every identical singleton RDATA, enabling wire-to-work amplifica…
CVE-2026-870117.549.1—Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in …
CVE-2026-548747.548.0—Excessive Memory Use Buffering DTLS Records for a Future Epoch
CVE-2026-685312.138.1—Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped…
CVE-2026-864326.933.9—commonmark 2.0.0 before 2.8.4 Denial of Service via XML
CVE-2026-542247.131.6—Denial of Service in UBB.threads
CVE-2025-323945.329.9—AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
CVE-2026-823094.328.9—Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DN…
CVE-2026-239345.127.0—Frontend DoS via the validate.api.exists action
CVE-2026-239305.326.9—Frontend DoS via the popup.testtriggerexpr action
CVE-2026-1044238.725.6—Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification
CVE-2026-1044318.725.6—Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
CVE-2026-1044256.921.1—Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions
CVE-2026-103880—8.6—Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored…
CVE-2026-85946.27.4—Text::LineFold versions through 2019.001 for Perl duplicate the output based on the num…
CVE-2026-843104.87.1—pypdf: Possible long runtimes/large memory usage when retrieving outlines

Most-affected vendors