boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-406

Weakness type CWE-406 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
651

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▅█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 2 · 2026-08 1 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-00288.684.5KEVPAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
CVE-2026-680806.549.5—Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
CVE-2026-500455.338.0—'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-546098.637.7—QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST…
CVE-2026-862025.326.9—PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
CVE-2026-165154.78.9—ICMPv6 error messages sent for multicast-destined packets and non-unique source address…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
nlnet labs1
palo alto networks1
pmmp1
quiet-terminal-interactive1
zephyrproject1