boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-407

Weakness type CWE-407 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
64610

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 19 · 2026-07 21 · 2026-08 15

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-434857.586.5.NET and Visual Studio Denial of Service Vulnerability
CVE-2024-434847.586.0.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2024-434837.585.7.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-559688.763.0Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVE-2026-548928.750.6Plug: quadratic-time decoding of nested query/body parameters enables denial of service
CVE-2026-556858.750.3React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-660468.749.5Expat Denial of Service via storeAtts() Quadratic Complexity
CVE-2026-646446.349.4Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-443906.947.3Unbounded name compression in certain cases causes degradation of service
CVE-2026-412926.647.3Long list of incoming EDNS options degrades performance
CVE-2026-425047.544.2Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-704538.742.3rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
CVE-2026-32766.339.9Potential DoS via quadratic complexity in unicodedata.normalize()
CVE-2026-590948.738.9Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Do…
CVE-2026-687508.236.9Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exh…
CVE-2026-568605.936.9Avoid quadratic complexity in resolvePath in net/url
CVE-2026-456645.336.8ImageMagick: Policy Bypass in MNG coder could
CVE-2026-582268.736.6Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
CVE-2026-598808.736.2Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVE-2026-598697.535.5js-yaml: YAML merge-key chains can force quadratic CPU consumption

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
nodeca5
lepture4
messagepack-csharp3
microsoft3
nlnet labs3
andialbrecht2
elastic2
go standard library2
python software foundation2
apache1
bytedance1
davegamble1
elixir-mint1
elixir-plug1
elysiajs1