boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-476

Weakness type CWE-476 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
6373731

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▁▂▂▁▂▁▂▁▂▂▂▂▁▂▂▁▁▁▁▁▁▅█▆▃

2025-09 16 · 2025-10 14 · 2025-11 0 · 2025-12 1 · 2026-01 3 · 2026-02 3 · 2026-03 2 · 2026-04 3 · 2026-05 85 · 2026-06 135 · 2026-07 100 · 2026-08 42

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-215256.291.5KEVWindows Remote Access Connection Manager Denial of Service Vulnerability
CVE-2025-220375.599.2ksmbd: fix null pointer dereference in alloc_preauth_hash()
CVE-2023-38665.595.1ksmbd: validate session id and tree id in the compound request
CVE-2024-214047.584.8.NET Denial of Service Vulnerability
CVE-2026-32387.584.5Samba: denial of service against ad dc wins server
CVE-2024-382337.583.0Windows Networking Denial of Service Vulnerability
CVE-2024-382327.582.0Windows Networking Denial of Service Vulnerability
CVE-2024-213566.580.0Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2023-217007.574.7Windows iSCSI Discovery Service Denial of Service Vulnerability
CVE-2024-270538.874.4wifi: wilc1000: fix RCU usage in connect path
CVE-2026-208757.573.7Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-578757.571.1GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
CVE-2026-212437.569.0Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-591327.568.4Windows TCP/IP Denial of Service Vulnerability
CVE-2026-427647.564.8NULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2025-381915.563.5ksmbd: fix null pointer dereference in destroy_previous_session
CVE-2026-404057.562.4Windows TCP/IP Denial of Service Vulnerability
CVE-2026-427665.961.9Possible NULL Dereference in Password-Based CMS Decryption
CVE-2026-320717.561.9Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-591386.561.4Microsoft Remote Registry Service Denial of Service Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux426
microsoft30
zephyrproject8
free5gc5
gnu5
mongodb5
red hat5
adobe4
canonical4
ggml-org4
ibm4
mcdope4
openssl4
qnap systems4
apple3