boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-552

Weakness type CWE-552 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
63534

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▃▃██▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 9 · 2026-06 5 · 2026-07 5 · 2026-08 17 · 2026-09 16 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-175199.199.9KEVApache Flink directory traversal attack: reading remote files through the REST API
CVE-2025-113717.599.8KEVGladinet CentreStack and TrioFox Local File Inclusion Flaw
CVE-2016-37155.599.5KEVImageMagick ImageMagick
CVE-2017-166517.898.8KEVRoundcube Roundcube Webmail
CVE-2023-366647.890.2——
CVE-2021-290247.575.6——
CVE-2024-214039.070.3—Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulner…
CVE-2025-663897.566.5——
CVE-2026-546297.560.4—Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server…
CVE-2026-579907.459.0—Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-118419.456.9—CVE-2026-11841
CVE-2026-406249.356.2—AVer PTC cameras Files or Directories Accessible to External Parties
CVE-2026-736539.454.7—Vitest: Browser Mode provider commands bypass the file-access permission gate
CVE-2025-06204.953.2—Samba: smbd doesn't pick up group membership changes when re-authenticating an expired …
CVE-2026-457219.053.1—Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-634907.551.0—Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix …
CVE-2026-630408.149.1—Apache InLong: Missing authorization in StreamSource forceDelete
CVE-2026-630428.149.1—Apache InLong: Missing authorization on DataNode management endpoints
CVE-2026-737058.847.7—Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fab…
CVE-2026-404256.947.0—MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Pa…

Most-affected vendors