boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-606

Weakness type CWE-606 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
27270

Monthly trend

▃▂▅▅▄█▅▁

2026-03 2 · 2026-04 1 · 2026-05 5 · 2026-06 4 · 2026-07 3 · 2026-08 8 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-15197.574.9—Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-629017.567.9—.NET Denial of Service Vulnerability
CVE-2026-416065.364.5—Apache Thrift: c_glib dispatch stack overflow
CVE-2026-338917.558.2—Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-425617.556.7—Python-Multipart: Denial of Service via unbounded multipart part headers
CVE-2026-59505.355.0—Unbounded resend loop in BIND 9 resolver
CVE-2026-398207.554.5—Quadratic string concatentation in consumeComment in net/mail
CVE-2026-338147.554.4—Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/in…
CVE-2026-119728.252.1—tarfile opened in streaming mode mishandles EOF
CVE-2026-442897.550.9—protobufjs: Denial of service through unbounded protobuf recursion
CVE-2026-662766.549.5—Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
CVE-2026-675546.549.5—Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of s…
CVE-2026-680776.549.5—Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
CVE-2026-271456.546.4—Inefficient candidate hostname parsing in crypto/x509
CVE-2026-203018.645.4—Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of S…
CVE-2026-557316.643.7—Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent
CVE-2026-714395.342.7—Mermaid radar diagrams are vulnerable to DoS
CVE-2026-857308.242.4—smol-toml: Denial of Service via malformed TOML documents
CVE-2026-101438.741.9—kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
CVE-2026-165995.129.1—Denial of Service in GNU wget

Most-affected vendors