boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-617

Weakness type CWE-617 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1591470

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▅▄█▁

2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 11 · 2026-06 36 · 2026-07 28 · 2026-08 20 · 2026-09 44 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-138787.595.2—Malformed BRID/HHIT records can cause named to terminate unexpectedly
CVE-2020-202116.584.4——
CVE-2026-59467.576.4—Invalid handling of CLASS != IN
CVE-2026-458157.562.5—Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
CVE-2026-415237.558.7—vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows …
CVE-2026-271357.558.0—nghttp2 Denial of service: Assertion failure due to the missing state validation
CVE-2025-156845.553.0—Open5GS CER init.c diam_log_func assertion
CVE-2026-907855.552.4—Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion
CVE-2026-907865.552.4—Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion
CVE-2026-529547.552.1—libceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-527186.551.9—Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser …
CVE-2026-929718.751.7—InternLM LMDeploy through 0.17.0 Assertion Denial of Service
CVE-2026-863176.951.6—ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
CVE-2024-358845.551.0—udp: do not accept non-tunnel GSO skbs landing in a tunnel
CVE-2026-761637.550.3—named aborts on a TKEY query when the user configuration has no global options statement
CVE-2023-528875.550.3—net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rt…
CVE-2026-555147.150.0—vLLM denial of service via prompt embeds on M-RoPE models
CVE-2026-443197.549.6—free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co…
CVE-2022-493255.549.1—tcp: add accessors to read/set tp->snd_cwnd
CVE-2026-372287.548.8——

Most-affected vendors