boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-497

Weakness type CWE-497 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
93881

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▆█▅▇▁

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 19 · 2026-07 28 · 2026-08 14 · 2026-09 23 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-319555.599.6KEVWindows Kernel Information Disclosure Vulnerability
CVE-2024-139997.378.8—Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure
CVE-2025-342837.162.8—Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
CVE-2026-713307.562.4—Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2024-139986.060.6—Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
CVE-2026-697235.758.1—Windows Kernel Information Disclosure Vulnerability
CVE-2026-148089.351.1—PROG MIS|Prog Management System - Exposure of Sensitive Information
CVE-2026-561248.748.7—phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVE-2018-253588.746.1—D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
CVE-2025-464216.845.4—Libsoup: information disclosure may leads libsoup client sends authorization header to …
CVE-2026-449459.144.7—Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-275536.544.7—Information Disclosure via Schema Path Manipulation
CVE-2026-813875.544.2—Microsoft Excel Information Disclosure Vulnerability
CVE-2026-813945.544.2—Microsoft Excel Information Disclosure Vulnerability
CVE-2026-759286.943.0—Brushfire unauthenticated information disclosure
CVE-2026-691276.941.1—Kirby: System path exposure from error messages in the REST API
CVE-2026-502946.241.1—Windows Kernel Information Disclosure Vulnerability
CVE-2026-419286.940.7—Vvveb < 1.0.8.2 Information Disclosure via Cron Controller
CVE-2026-688425.539.1—Windows MIDI Service Module Information Disclosure Vulnerability
CVE-2026-693155.539.1—Windows License Manager Information Disclosure Vulnerability

Most-affected vendors