boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-538

Weakness type CWE-538 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
18180

Monthly trend

▂▁▂█▂▄▅▁

2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 1 · 2026-08 3 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-695075.758.2—Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-492988.855.6—Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
CVE-2016-200249.353.0—ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation
CVE-2026-192295.544.9—SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information…
CVE-2026-466178.739.4—Fission runtime pods automount the fission-fetcher service-account token into the user …
CVE-2026-505654.936.6—Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-su…
CVE-2026-155747.536.1—Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full cha…
CVE-2026-127625.332.3—Insertion of Sensitive Information into Externally-Accessible File in IBM Business Auto…
CVE-2026-54345.924.3—Improper storage of sensitive information
CVE-2026-102545.523.9—SourceCodester Pet Grooming Management Software admin file information disclosure
CVE-2025-363726.521.1—IBM® Db2® could disclose sensitive information to an authenticated user from the monito…
CVE-2026-291142.317.7——
CVE-2026-500995.110.9—Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file…
CVE-2026-673616.910.8—Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory …
CVE-2019-257175.39.4—Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
CVE-2026-574426.98.1—MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied a…
CVE-2026-258272.34.2——
CVE-2026-801753.32.6——

Most-affected vendors