boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-506

Weakness type CWE-506 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
29229

Monthly trend

▂▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▂▁▁▂▁▁▂▁▃▂▄█▂▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 4 · 2026-08 11 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-300668.699.4KEVtj-actions changed-files GitHub Action
CVE-2024-49788.798.0KEVMalicious Code in Justice AV Solutions (JAVS) Viewer
CVE-2025-543137.591.2KEVPrettier eslint-config-prettier
CVE-2025-301548.683.7KEVMultiple Reviewdog actions were compromised during a specific time period
CVE-2026-336349.476.2KEVTrivy ecosystem supply chain briefly compromised
CVE-2026-480279.370.2KEVCompromised Nx Console version 18.95.0
CVE-2025-593749.367.1KEVASUS Live Update
CVE-2026-453219.663.2KEVMalware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SS…
CVE-2026-83989.360.3KEVDaemon Daemon Tools Lite
CVE-2024-309410.099.7—Xz: malicious code in distributed source
CVE-2026-180729.886.8—Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - …
CVE-2026-742329.355.6—Zbtlink MQWrt yunmgrd Cloud C2 Implant
CVE-2026-776499.855.1——
CVE-2026-776509.855.1——
CVE-2026-776519.855.1——
CVE-2026-667479.354.7—ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
CVE-2026-4641210.053.9—Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-675959.253.8—VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
CVE-2026-481589.350.3—use-context-selector was vulnerable to malicious code execution via compromised commits
CVE-2026-481599.350.3—use-reducer-async was vulnerable to malicious code execution via compromised commits

Most-affected vendors