boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-407

Weakness type CWE-407 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1311280

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▅█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 2 · 2026-05 7 · 2026-06 19 · 2026-07 21 · 2026-08 23 · 2026-09 45 · 2026-10 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-434857.587.2—.NET and Visual Studio Denial of Service Vulnerability
CVE-2024-434847.586.7—.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2024-434837.586.5—.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-559688.762.5—Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVE-2026-548928.759.9—Plug: quadratic-time decoding of nested query/body parameters enables denial of service
CVE-2026-412926.656.0—Long list of incoming EDNS options degrades performance
CVE-2026-687508.255.1—Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exh…
CVE-2026-590948.754.8—Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Do…
CVE-2026-660468.753.1—Expat Denial of Service via storeAtts() Quadratic Complexity
CVE-2026-713217.553.1—Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body …
CVE-2026-750058.753.0—Apache APISIX: Unauthenticated CPU-exhaustion DoS
CVE-2026-827608.252.9—Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in
CVE-2026-404766.952.7—graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged…
CVE-2026-443906.952.1—Unbounded name compression in certain cases causes degradation of service
CVE-2026-32766.352.1—Potential DoS via quadratic complexity in unicodedata.normalize()
CVE-2026-556858.751.8—React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-907768.750.9—Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing
CVE-2026-634467.550.9—Suricata app-layer: passed flows can retain transactions, causing resource exhaustion
CVE-2026-691847.550.9—c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains
CVE-2026-878228.750.2—t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.from…

Most-affected vendors