boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-470

Weakness type CWE-470 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
61602

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 7 · 2026-07 14 · 2026-08 14 · 2026-09 24 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-219859.8100.0KEVVMware vCenter Server
CVE-2026-820789.499.1KEVPaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
CVE-2026-656088.769.0—Grav before 2.0.9 Remote Code Execution via FlexDirectory
CVE-2026-420279.868.8—Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
CVE-2026-444169.868.2—Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
CVE-2026-867928.866.9—Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Sc…
CVE-2026-584009.166.8—GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configur…
CVE-2026-623799.863.6—OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createC…
CVE-2026-447958.861.9—Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types
CVE-2026-465629.860.8—Yamcs: Remote Code Execution via Mission Database algorithm override
CVE-2026-633175.656.8—Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descripto…
CVE-2026-5510710.055.0—Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → p…
CVE-2026-555599.854.5—Yamcs: Remote Code Execution via instance-template argument YAML injection (createInsta…
CVE-2026-60207.254.4—ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via '…
CVE-2026-175937.254.2—Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
CVE-2026-418719.853.2—Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch RES…
CVE-2026-467186.551.0—Apache Calcite: A user-controled model can load arbitrary classes, leading to code exec…
CVE-2026-131818.150.6—RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.…
CVE-2026-418708.850.1—Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch S…
CVE-2026-799878.749.3—Low-privilege RCE through element-search eager loading

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache9
ibm4
jenkins project2
messagepack-csharp2
mongodb2
progress2
red hat2
statamic2
yamcs2
aws1
cakephp1
craftcms1
dell1
devitemsllc1
djust-org1