boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-415

Weakness type CWE-415 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2291296

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▂▂▂▂▂▂▂▁▂▁▁▂▂▂▁▂▂▁▁▂▁▁▂▄▄▆▄█▁

2025-11 1 · 2025-12 0 · 2026-01 4 · 2026-02 0 · 2026-03 0 · 2026-04 7 · 2026-05 16 · 2026-06 17 · 2026-07 30 · 2026-08 16 · 2026-09 39 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-49908.898.4KEVAdobe Acrobat and Reader
CVE-2014-05028.897.8KEVAdobe Flash Player
CVE-2021-226006.693.6KEVDouble Free in net/packet/af_packet.c leading to priviledge escalation
CVE-2025-622157.093.1KEVWindows Kernel Elevation of Privilege Vulnerability
CVE-2026-338249.875.2KEVWindows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVE-2020-98597.856.1KEVApple Multiple Products
CVE-2024-300978.876.8—Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnera…
CVE-2026-187987.574.0—QUIC Server May Trigger Double Free When Processing INITIAL Packet
CVE-2025-329888.271.0—Gnutls: vulnerability in gnutls othername san export
CVE-2026-89259.863.9—SASL double-free
CVE-2023-353717.861.1—Microsoft Office Remote Code Execution Vulnerability
CVE-2026-774939.860.8—Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-663737.557.5——
CVE-2026-336307.556.5—c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely tri…
CVE-2026-775048.855.7—Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-800808.855.7—Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-338117.555.5—Crash when handling long CNAME response in net
CVE-2026-693228.054.0—Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-141647.552.8—Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered…
CVE-2026-550078.152.4—Microsoft Exchange Server Remote Code Execution Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux117
microsoft49
red hat6
apple5
zephyrproject4
freerdp3
cisco2
mongodb2
openssl2
samsung2
adobe1
alsa-project1
aws1
c-ares1
curl1