boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-476

Weakness type CWE-476 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
8485581

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▁▂▂▁▂▂▂▁▂▂▂▂▁▂▂▁▁▁▁▂▁▅█▇▆▆▁

2025-11 0 · 2025-12 1 · 2026-01 6 · 2026-02 7 · 2026-03 10 · 2026-04 8 · 2026-05 85 · 2026-06 135 · 2026-07 119 · 2026-08 87 · 2026-09 95 · 2026-10 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-215256.291.7KEVWindows Remote Access Connection Manager Denial of Service Vulnerability
CVE-2025-220375.599.3—ksmbd: fix null pointer dereference in alloc_preauth_hash()
CVE-2023-38665.595.8—ksmbd: validate session id and tree id in the compound request
CVE-2020-10698.890.2—Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-214047.585.5—.NET Denial of Service Vulnerability
CVE-2024-382337.583.8—Windows Networking Denial of Service Vulnerability
CVE-2020-202126.583.1——
CVE-2024-382327.582.8—Windows Networking Denial of Service Vulnerability
CVE-2024-213566.580.8—Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-32387.580.3—Samba: denial of service against ad dc wins server
CVE-2023-217007.575.7—Windows iSCSI Discovery Service Denial of Service Vulnerability
CVE-2024-270538.875.7—wifi: wilc1000: fix RCU usage in connect path
CVE-2026-630767.575.0—Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
CVE-2026-208757.574.4—Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-212437.572.0—Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-389997.571.6——
CVE-2025-381915.570.0—ksmbd: fix null pointer dereference in destroy_previous_session
CVE-2026-15847.569.9—Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder
CVE-2026-320717.566.4—Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-404057.566.4—Windows TCP/IP Denial of Service Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux466
microsoft42
adobe20
red hat19
gnu14
zephyrproject12
ibm10
nvidia8
mongodb7
openssl7
wireshark foundation7
apache6
envoyproxy6
apple5
free5gc5