boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-494

Weakness type CWE-494 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
48464

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▃▂▇█▂

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 14 · 2026-09 16 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-407998.898.3KEVD-Link DNR-322L
CVE-2025-155567.777.4KEVNotepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
CVE-2021-441683.357.2KEVFortinet FortiOS
CVE-2026-35027.823.7KEVTrueConf Client Update Integrity Verification Bypass
CVE-2026-854279.243.9—MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MI…
CVE-2025-692637.538.9—pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies
CVE-2026-306129.833.6——
CVE-2026-650819.833.0——
CVE-2026-480469.327.0—Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC H…
CVE-2026-663989.425.5—phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
CVE-2026-820219.025.0—Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference
CVE-2026-592868.123.6—Spring for GraphQL loads Untrusted Resources in GraphiQL support
CVE-2026-650978.822.2——
CVE-2026-636969.120.8——
CVE-2026-450589.420.4—electerm: Import unsafe bookmark data could lead to unsafe operation when click local t…
CVE-2026-556988.820.3—pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc…
CVE-2026-921287.519.8——
CVE-2026-799637.417.2——
CVE-2026-90379.316.8—Download of code without integrity check in XCharge C6
CVE-2026-539707.515.4—ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb

Most-affected vendors