boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-610

Weakness type CWE-610 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
20191

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇██▅▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 5 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-2759310.099.8KEVDeadBolt Ransomware
CVE-2026-573018.848.2——
CVE-2026-343278.247.0—Microsoft Partner Center Spoofing Vulnerability
CVE-2026-108167.145.7—Arbitrary File Read (Unauthenticated)
CVE-2026-553897.543.9—datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref`…
CVE-2026-553907.542.8—Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path trav…
CVE-2026-155838.642.7—SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
CVE-2026-190325.342.7—jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.f…
CVE-2026-629607.437.4—Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UN…
CVE-2026-765725.137.2—pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
CVE-2026-792568.336.1——
CVE-2026-127882.131.9—zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml …
CVE-2026-457608.130.3—Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
CVE-2026-685626.229.5—Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosur…
CVE-2026-789664.323.6——
CVE-2026-813758.322.3—Confused Deputy in Application Integration allows Internal File Read
CVE-2026-128795.920.6—Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-04184.314.2—Certain NETGEAR devices allow administrators to tamper with system
CVE-2026-953768.09.0——
CVE-2026-218104.40.1—HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference…

Most-affected vendors