boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-459

Weakness type CWE-459 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
24160

Monthly trend

▂▁▁▁▁▁▁▂▁▁▁▂▁▂▂▁▂▁▁▂▁▁▁▁▁▁▁▃▂█

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 2 · 2026-08 11

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-471785.545.1scsi: target: core: Avoid smp_processor_id() in preemptible code
CVE-2026-424927.539.4vIRQ event channel binding may break Xenstore
CVE-2026-115767.538.2
CVE-2026-527368.737.1ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
CVE-2025-63389.232.9Possible denial of service with multiple incoming connections to a Schannel based serve…
CVE-2026-527336.526.5ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork …
CVE-2026-190192.923.2poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence…
CVE-2026-674422.023.2FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup
CVE-2026-50387.520.4multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
CVE-2026-194747.520.4@fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted u…
CVE-2026-688095.520.2Powerpoint Information Disclosure Vulnerability
CVE-2024-476745.516.1mm: avoid leaving partial pfn mappings around in error case
CVE-2024-579765.512.8btrfs: do proper folio cleanup when cow_file_range() failed
CVE-2024-579755.511.8btrfs: do proper folio cleanup when run_delalloc_nocow() failed
CVE-2025-219245.510.6net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns a…
CVE-2026-673345.110.1better-auth Stale Sessions Persist After User Deletion
CVE-2025-379087.88.2mm, slab: clean up slab->obj_exts always
CVE-2026-538675.38.2Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
CVE-2025-381775.55.9sch_hfsc: make hfsc_qlen_notify() idempotent
CVE-2026-96933.55.3Mattermost thread memberships persist after team removal, exposing private channel thre…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux7
zcashfoundation2
@fastify/multipart1
better-auth1
capgo1
eclipse foundation1
frangoteam1
imagination technologies1
mattermost1
microsoft1
multer1
poco-ai1
qt1
red hat1
sharp1