boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-426

Weakness type CWE-426 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
76682

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▂▆▅█▆▁

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 2 · 2026-03 1 · 2026-04 2 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 19 · 2026-09 13 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2012-18547.897.5KEVMicrosoft Visual Basic for Applications (VBA)
CVE-2022-220477.897.2KEVWindows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVE-2024-301007.866.7—Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-277437.857.8—Microsoft System Center Elevation of Privilege Vulnerability
CVE-2026-630938.756.6—Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
CVE-2024-352609.856.0—Microsoft Dataverse Remote Code Execution Vulnerability
CVE-2024-436167.854.2—Microsoft Office Remote Code Execution Vulnerability
CVE-2026-557699.454.1—CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG f…
CVE-2026-166748.853.2—IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty
CVE-2026-457219.053.1—Algernon: handler.lua discovery walks parent directories above the server root
CVE-2023-368987.852.1—Tablet Windows User Interface Application Core Remote Code Execution Vulnerability
CVE-2026-748729.350.7—openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool
CVE-2026-209437.049.9—Microsoft Office Click-To-Run Remote Code Execution Vulnerability
CVE-2026-428306.549.1—Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVE-2026-781559.942.0—Untrusted Search Path in StackGres
CVE-2026-444779.441.8—CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and…
CVE-2026-570976.840.8—Microsoft XML Security Feature Bypass Vulnerability
CVE-2024-435767.840.2—Microsoft Office Remote Code Execution Vulnerability
CVE-2026-491457.539.8—App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a pr…
CVE-2026-561747.837.5—Windows Narrator Braille Elevation of Privilege Vulnerability

Most-affected vendors