boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-459

Weakness type CWE-459 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
57490

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂█▇▄

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 2 · 2026-08 19 · 2026-09 16 · 2026-10 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-527368.747.6—ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
CVE-2026-424927.547.5—vIRQ event channel binding may break Xenstore
CVE-2026-777616.347.5—Cross-Document Parser State Contamination in misp-stix
CVE-2026-877767.547.4—compression vulnerable to Denial of Service via memory leak on premature response close
CVE-2021-471785.546.1—scsi: target: core: Avoid smp_processor_id() in preemptible code
CVE-2026-889325.343.1—multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
CVE-2026-194747.540.4—@fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted u…
CVE-2026-190192.940.1—poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence…
CVE-2026-50387.540.0—multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
CVE-2026-115767.537.9——
CVE-2026-850439.136.3——
CVE-2026-527336.535.8—ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork …
CVE-2026-688095.535.7—Powerpoint Information Disclosure Vulnerability
CVE-2025-63389.234.9—Possible denial of service with multiple incoming connections to a Schannel based serve…
CVE-2026-953036.528.3——
CVE-2026-875496.528.3——
CVE-2026-1063759.627.2——
CVE-2026-822362.326.7—File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion
CVE-2026-770377.526.2—multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
CVE-2026-674422.023.4—FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup

Most-affected vendors