boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-480

Weakness type CWE-480 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
660

Monthly trend

▅▅█▅▅▁

2026-05 1 · 2026-06 1 · 2026-07 2 · 2026-08 1 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-634217.550.4—Keystone: `graphql.maxTake` bypass with negative `take`
CVE-2026-484977.532.6—Envoy: Abnormal process termination in DNS UDP filter
CVE-2026-150439.830.6—DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL ope…
CVE-2026-431149.428.8—netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
CVE-2026-796437.324.3——
CVE-2026-447226.21.5—pyzipper: Encryption bypass for small files encrypted with pyzipper

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
danifus1
dell1
envoyproxy1
hmbrand1
keystonejs1
linux1