boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-428

Weakness type CWE-428 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43400

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▁▁▂█▁▂▂▁

2025-11 0 · 2025-12 2 · 2026-01 6 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 23 · 2026-07 1 · 2026-08 2 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-153587.564.5—Path Traversal Vulnerability
CVE-2024-434577.847.8—Windows Setup and Deployment Elevation of Privilege Vulnerability
CVE-2024-582888.730.2—Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation
CVE-2021-477678.513.8—10-Strike Network Inventory Explorer Pro 9.31 - 'srvInventoryWebServer' Unquoted Servic…
CVE-2021-478068.513.8—Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path
CVE-2021-477928.512.7—Remote Mouse 4.002 - Unquoted Service Path
CVE-2021-478078.512.7—Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path
CVE-2024-583158.512.6—Tosibox Key Service 3.3.0 Local Privilege Escalation via Unquoted Service Path
CVE-2022-509718.512.0—Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
CVE-2020-371008.511.1—Sync Breeze Enterprise 12.4.18 - Unquoted Service Path
CVE-2026-258658.58.8—Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
CVE-2026-668398.48.8——
CVE-2016-200948.58.6—AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
CVE-2026-814697.88.0——
CVE-2026-187557.37.7—GV-ASManager DLL hijacking vulnerability
CVE-2025-713268.57.2—AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
CVE-2019-252858.57.0—Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service…
CVE-2020-369878.56.6—Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
CVE-2016-200878.56.4—Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
CVE-2016-200888.56.4—Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
comodo2
realtek2
syncbreeze2
10-strike1
alps1
anydesk1
argus1
avast1
binisoft1
brother1
dell1
diskboss1
dupscout1
gearboxcomputers1
genexus1