boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-667

Weakness type CWE-667 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
156682

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▅▂▂▂▃▁▂▂▁▃▂▂▂▁▂▁▁▁▁▁▁▁▁▁▅█▅▁▂▁

2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 15 · 2026-06 29 · 2026-07 16 · 2026-08 1 · 2026-09 4 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-17827.082.1KEVApple Multiple Products
CVE-2025-435107.827.0KEVApple Multiple Products
CVE-2024-409805.553.6—drop_monitor: replace spin_lock by raw_spin_lock
CVE-2024-410365.553.4—net: ks8851: Fix deadlock with the SPI chip variant
CVE-2024-359715.551.1—net: ks8851: Handle softirqs at the end of IRQ thread to fix hang
CVE-2026-530499.845.2—gfs2: add some missing log locking
CVE-2021-475875.543.9—net: systemport: Add global locking for descriptor lifecycle
CVE-2026-460317.542.7—net: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2024-394685.542.7—smb: client: fix deadlock in smb2_find_smb_tcon()
CVE-2026-640689.840.8—netfs: Fix missing locking around retry adding new subreqs
CVE-2024-580878.140.8—ksmbd: fix racy issue from session lookup and expire
CVE-2021-470415.540.3—nvmet-tcp: fix incorrect locking in state_change sk callback
CVE-2026-529467.538.2—fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-530718.835.0—Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-640679.834.7—netfs: Fix missing barriers when accessing stream->subrequests locklessly
CVE-2024-566945.533.1—bpf: fix recursive lock when verdict program return SK_PASS
CVE-2024-274355.531.6—nvme: fix reconnection fail due to reserved tag allocation
CVE-2024-359985.531.5—smb3: fix lock ordering potential deadlock in cifs_sync_mid_result
CVE-2022-497685.531.0—9p: trans_fd/p9_conn_cancel: drop client lock earlier
CVE-2026-643747.530.4—sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux141
xen3
apple2
nvidia2
dell1
google1
nationalsecurityagency1
nezhahq1
open-telemetry1
red hat1
ruby-concurrency1
zephyrproject1