boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-416

Weakness type CWE-416 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2113125412

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▂▂▁▂▁▂▁▂▂▁▁▁▂▁▁▁▁▁▁▂▃█▆▃

2025-09 60 · 2025-10 33 · 2025-11 2 · 2025-12 0 · 2026-01 28 · 2026-02 7 · 2026-03 3 · 2026-04 58 · 2026-05 170 · 2026-06 499 · 2026-07 352 · 2026-08 137

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-39929.899.6KEVVMware ESXi
CVE-2018-159827.899.6KEVAdobe Flash Player
CVE-2021-264118.899.6KEVInternet Explorer Memory Corruption Vulnerability
CVE-2021-2289310.098.7KEVIvanti Pulse Connect Secure
CVE-2024-10867.898.0KEVUse-after-free in Linux kernel's netfilter: nf_tables component
CVE-2024-96809.897.6KEVMozilla Firefox
CVE-2025-298247.896.2KEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-25867.895.4KEVLinux Kernel
CVE-2021-344867.894.9KEVWindows Event Tracing Elevation of Privilege Vulnerability
CVE-2026-52818.891.5KEVGoogle Dawn
CVE-2024-369717.884.7KEVnet: fix __dst_negative_advice() race
CVE-2026-688207.026.2KEVWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2024-300809.898.6Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2025-217608.198.4ndisc: extend RCU protection in ndisc_send_skb()
CVE-2026-456579.896.5Windows Kernel Remote Code Execution Vulnerability
CVE-2024-434919.895.9Microsoft Windows Update Remote Code Execution Vulnerability
CVE-2025-266708.195.4Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
CVE-2025-274808.195.1Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2024-300897.894.3Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2025-217597.893.9ipv6: mcast: extend RCU protection in igmp6_send()

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux944
google462
microsoft440
apple42
mozilla21
zephyrproject16
foxit software15
adobe13
red hat13
imagemagick7
sparklemotion7
freebsd6
mongodb6
apache5
imagination technologies5