boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-440

Weakness type CWE-440 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
12110

Monthly trend

▃▁▁▃▁▆▆▁▆█▃

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 2 · 2026-07 0 · 2026-08 2 · 2026-09 3 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-425346.952.3—Jostle logic bypass degrades resolution performance
CVE-2026-936758.850.8—Langflow OSS is affected by multiple vulnerabilities
CVE-2026-88068.748.9—Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
CVE-2026-33446.937.4—WatchGuard Firebox System Integrity Check Bypass
CVE-2026-351913.727.4—QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-427526.521.3—WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
CVE-2026-493164.117.4—Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
CVE-2026-659325.315.1—BT122 stops advertising
CVE-2026-976877.614.1—urllib3: HTTPS proxy TLS configuration may be ignored or overridden
CVE-2026-659347.12.9—BT122 plaintext pause encryption request causes DOS
CVE-2025-139406.71.9—WatchGuard Firebox Boot Time System Integrity Check Bypass
CVE-2026-167697.10.8—RS9116W/SiWx917 plaintext pause encryption request causes DOS

Most-affected vendors