boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-653

Weakness type CWE-653 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23211

Monthly trend

▂▂▁▁▁▁▁▁▁▁▁▁▁▁▆▅█▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 3 · 2026-07 6 · 2026-08 2 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-215906.776.6KEVJunos OS: An local attacker with shell access can execute arbitrary code
CVE-2026-534219.865.4—Apache Syncope: Remote Code Execution via Scripted Connector
CVE-2026-427827.257.2—Apache Syncope: Post-auth RCE via Groovy static
CVE-2026-4400510.056.0—vm2: Sandbox escape
CVE-2026-4399710.054.0—vm2: Sandbox Escape
CVE-2026-630719.853.4—Apache Syncope: RCE via Groovy Sandbox bypass
CVE-2026-534059.853.2—Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
CVE-2026-440099.851.9—vm2: Sandbox Breakout Through Null Proto Exception
CVE-2026-157385.849.2—Cross-namespace traffic interception via incorrect route precedence ordering in AWS Loa…
CVE-2026-656358.342.4—Boruta dynamic client registration allows creation of over-privileged OAuth clients
CVE-2025-40839.137.0—Process isolation bypass using "javascript:" URI links in cross-origin frames
CVE-2026-571357.633.6—PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network …
CVE-2026-122959.631.1—Sandbox escape in the DOM: Navigation component
CVE-2026-122979.631.1—Sandbox escape due to incorrect boundary conditions in the Networking component
CVE-2026-622468.527.8—Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL d…
CVE-2026-956998.420.3—MrSteam iSteamX Improper Isolation or Compartmentalization
CVE-2026-970295.714.2—Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group
CVE-2026-153662.44.5——
CVE-2026-829648.84.2—Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx…
CVE-2026-713254.84.0—Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

Most-affected vendors