boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-415

Weakness type CWE-415 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
168751

Monthly trend

▁▁▁▁▁▁▂▂▂▆▂▂▂▃▂▃▂▂▃▂▂▃▂▃▂▃▃▁▁▂▁▁▃▆▇█▄

2025-09 7 · 2025-10 6 · 2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 0 · 2026-03 0 · 2026-04 7 · 2026-05 16 · 2026-06 17 · 2026-07 21 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-338249.899.5KEVWindows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVE-2024-300978.875.6Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnera…
CVE-2026-627667.072.6Windows Kerberos Elevation of Privilege Vulnerability
CVE-2023-353717.859.6Microsoft Office Remote Code Execution Vulnerability
CVE-2026-338117.554.2Crash when handling long CNAME response in net
CVE-2024-267827.850.8mptcp: fix double-free on socket dismantle
CVE-2024-382477.850.2Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-410737.849.3nvme: avoid double free special payload
CVE-2024-358357.849.1net/mlx5e: fix a double-free in arfs_create_groups
CVE-2024-502767.848.9net: vertexcom: mse102x: Fix possible double free of TX skb
CVE-2024-502157.847.4nvmet-auth: assign dh_key to NULL after kfree_sensitive
CVE-2026-506857.547.0Windows DHCP Server Remote Code Execution Vulnerability
CVE-2024-467367.846.4smb: client: fix double put of @cfile in smb2_rename_path()
CVE-2024-435147.846.2Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2025-277307.846.1Windows Digital Media Elevation of Privilege Vulnerability
CVE-2026-89259.845.7SASL double-free
CVE-2026-628898.144.2Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-663737.541.0
CVE-2024-501525.539.6smb: client: fix possible double free in smb2_set_ea()
CVE-2026-208327.839.4Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privileg…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux107
microsoft29
red hat4
freerdp3
zephyrproject3
apple2
alsa-project1
aws1
cisco1
curl1
eclipse foundation1
ffmpeg1
ggml-org1
go standard library1
libssh21