boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-470

Weakness type CWE-470 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
30291

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 7 · 2026-07 13 · 2026-08 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-219859.8100.0KEVVMware vCenter Server
CVE-2026-444169.864.6Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
CVE-2026-656088.755.3Grav before 2.0.9 Remote Code Execution via FlexDirectory
CVE-2026-465629.853.1Yamcs: Remote Code Execution via Mission Database algorithm override
CVE-2026-447958.843.3Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types
CVE-2026-60207.243.0ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via '…
CVE-2026-633175.641.5Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descripto…
CVE-2026-131818.139.9RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.…
CVE-2026-84009.839.7Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and W…
CVE-2022-49939.139.6HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method disp…
CVE-2026-492877.438.1Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data …
CVE-2026-130519.137.6Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow att…
CVE-2026-467186.536.5Apache Calcite: A user-controled model can load arbitrary classes, leading to code exec…
CVE-2026-400089.835.5Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CVE-2026-536666.134.8React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router S…
CVE-2026-131878.127.2DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-551537.125.7mchange-commons-java contains elements susceptible to abuse via JNDI injection and "des…
CVE-2026-586598.425.5PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter
CVE-2026-633377.524.5RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enable…
CVE-2026-175937.223.5Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache4
ibm2
messagepack-csharp2
progress2
statamic2
devitemsllc1
getgrav1
getkirby1
jenkins project1
kludex1
lightning-ai1
masci1
nvidia1
rabbitmq1
remix-run1