boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-532

Weakness type CWE-532 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1681592

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▄▆█▂

2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 1 · 2026-03 2 · 2026-04 5 · 2026-05 14 · 2026-06 19 · 2026-07 22 · 2026-08 37 · 2026-09 53 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-214924.484.5KEVSamsung Mobile Devices
CVE-2025-249844.679.6KEVWindows NTFS Information Disclosure Vulnerability
CVE-2025-250026.865.0—Azure Local Cluster Information Disclosure Vulnerability
CVE-2026-542365.359.2—vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-648005.756.6——
CVE-2026-208186.252.6—Windows Kernel Information Disclosure Vulnerability
CVE-2026-193635.550.2—lmammino oidc-authorizer Lambda Authorizer handler.rs log file
CVE-2026-929188.749.3—admin3 through 3.0.0 Session Token Disclosure via Audit Log
CVE-2026-689696.549.0—Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audi…
CVE-2026-659456.548.7—Apache Ranger: Logs contain replayable JWT bearer tokens
CVE-2026-120537.548.2—Insertion of Sensitive Information into Log File in GitLab
CVE-2026-4920010.047.6—Acer Wave 7 router: Broken Access Control
CVE-2026-212225.547.1—Windows Kernel Information Disclosure Vulnerability
CVE-2026-667806.545.7—Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace …
CVE-2026-149488.745.3—Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensiti…
CVE-2026-851717.144.9—n8n before 1.123.73 Credential Exposure via Error Logging
CVE-2026-411846.042.6—ServiceAccount token disclosure via install-cni container logs
CVE-2024-96215.342.3—Io.quarkiverse.cxf:quarkus-cxf: quarkus cxf may log user password and secret to applica…
CVE-2024-312457.542.2—WordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerability
CVE-2024-312497.541.4—WordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vul…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm12
red hat10
dell9
microsoft9
apache7
mongodb7
apple6
arista networks5
brocade5
hclsoftware5
open-telemetry4
spring4
jahlives3
jetbrains3
renovatebot3