boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-61

Weakness type CWE-61 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
30301

Monthly trend

▂█▆▄

2026-05 2 · 2026-06 13 · 2026-07 10 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-544208.571.0KEVLiteSpeed cPanel Plugin
CVE-2026-492488.344.7OneDev: RCE through absolute-path symlink following allows low-privileged users to over…
CVE-2026-567488.744.5Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVE-2026-554479.638.8Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-528119.037.9Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-419378.633.7Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
CVE-2026-568768.632.4extract-zip unvalidated symlink path traversal
CVE-2026-556865.330.7Podman: WORKDIR symlink traversal vulnerability
CVE-2026-629926.929.6Smarty: Symlink path traversal out of trusted directories
CVE-2026-174592.124.8perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
CVE-2026-52236.522.1Crates in third party registries can override the cached source of other crates
CVE-2026-129588.517.3Arbitrary file write in Language Servers for AWS
CVE-2026-398227.814.4Root escape via symlink plus trailing slash in os
CVE-2026-534898.28.6containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint re…
CVE-2026-415793.38.6runc: Malicious image with /dev symlink can trigger limited host filesystem integrity v…
CVE-2026-477665.15.8crun follows rootfs /dev symlink while creating default devices
CVE-2026-568157.45.2
CVE-2026-477636.84.8pdm: Project-Local State and Config Writes Follow Symlinks
CVE-2025-432785.54.8
CVE-2026-132017.34.5Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enab…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat3
amazon web services1
apple1
containerd1
containers1
cribl1
dell1
givanz1
go standard library1
gogs1
huggingface1
langflow-ai1
litespeed technologies1
max-mapper1
moby1