boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-61

Weakness type CWE-61 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
45451

Monthly trend

▂▂█▆▆▆▁

2026-04 1 · 2026-05 2 · 2026-06 13 · 2026-07 10 · 2026-08 10 · 2026-09 9 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-544208.555.3KEVLiteSpeed cPanel Plugin
CVE-2026-910995.161.0—HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-567488.758.9—Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVE-2026-631259.950.0—Incus vulnerable to root RCE via image backup.yaml symlink
CVE-2026-554479.649.9—Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-419378.648.3—Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
CVE-2026-551686.547.3—Runtipi: Authenticated arbitrary file write via backup restore symlink planting
CVE-2026-492488.345.3—OneDev: RCE through absolute-path symlink following allows low-privileged users to over…
CVE-2026-629926.943.0—Smarty: Symlink path traversal out of trusted directories
CVE-2026-568768.642.5—extract-zip unvalidated symlink path traversal
CVE-2026-528119.038.8—Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-578255.738.7——
CVE-2026-174592.138.3—perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
CVE-2026-52236.533.6—Crates in third party registries can override the cached source of other crates
CVE-2026-556865.332.2—Podman: WORKDIR symlink traversal vulnerability
CVE-2026-413268.228.8—Kata Containers: CopyFile Policy Subversion via Symlinks
CVE-2026-970247.121.6—Flatpak: flatpak: arbitrary write in root context via path traversal in deploy director…
CVE-2026-970237.118.8—Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy …
CVE-2026-132017.318.1—Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enab…
CVE-2026-538028.413.5—rsync < 3.5.0 Arbitrary File Read via Symlink Following

Most-affected vendors