boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-552

Weakness type CWE-552 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
27230

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▁▁▁▁█▅▅▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 9 · 2026-06 5 · 2026-07 5 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-290247.574.3
CVE-2024-214039.069.0Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulner…
CVE-2025-663897.558.2
CVE-2026-579907.457.6Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-406249.354.9AVer PTC cameras Files or Directories Accessible to External Parties
CVE-2026-736539.448.1Vitest: Browser Mode provider commands bypass the file-access permission gate
CVE-2026-405646.540.2Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in …
CVE-2026-321855.538.7Microsoft Teams Spoofing Vulnerability
CVE-2024-564628.838.5IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
CVE-2026-118419.438.1CVE-2026-11841
CVE-2026-354405.537.5Microsoft Word Information Disclosure Vulnerability
CVE-2026-457219.036.6Algernon: handler.lua discovery walks parent directories above the server root
CVE-2018-251457.135.2Microhard Systems IPn4G 1.1.0 Configuration Disclosure via Authenticated Download
CVE-2026-597038.731.9repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint
CVE-2026-404256.930.8MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Pa…
CVE-2025-52738.229.1
CVE-2026-333806.328.5SQL Expressions Read File From Disk
CVE-2025-147717.327.9File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Defaul…
CVE-2026-87159.624.7Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration vi…
CVE-2026-199035.523.9SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft4
sourcecodester2
abb1
agentejo1
apache1
aver1
danelec1
grafana1
hahwul1
hashicorp1
ibm1
microhard systems1
nextcloud1
plane1
repomix1