boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-667

Weakness type CWE-667 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
135520

Monthly trend

▁▂▂▁▄▂▂▂▃▁▂▂▁▃▂▂▂▁▂▁▁▁▁▁▁▁▁▁▅█▃▁

2025-09 1 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 15 · 2026-06 29 · 2026-07 7 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-409805.552.3drop_monitor: replace spin_lock by raw_spin_lock
CVE-2024-410365.552.2net: ks8851: Fix deadlock with the SPI chip variant
CVE-2024-359715.549.8net: ks8851: Handle softirqs at the end of IRQ thread to fix hang
CVE-2021-475875.543.5net: systemport: Add global locking for descriptor lifecycle
CVE-2024-394685.542.7smb: client: fix deadlock in smb2_find_smb_tcon()
CVE-2021-470415.540.2nvmet-tcp: fix incorrect locking in state_change sk callback
CVE-2024-580878.140.1ksmbd: fix racy issue from session lookup and expire
CVE-2026-529467.537.9fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2024-566945.534.5bpf: fix recursive lock when verdict program return SK_PASS
CVE-2024-274355.533.1nvme: fix reconnection fail due to reserved tag allocation
CVE-2024-359985.532.6smb3: fix lock ordering potential deadlock in cifs_sync_mid_result
CVE-2026-530499.832.1gfs2: add some missing log locking
CVE-2024-359997.530.7smb3: missing lock when picking channel
CVE-2026-460317.530.2net: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2022-497685.529.99p: trans_fd/p9_conn_cancel: drop client lock earlier
CVE-2025-220775.527.7Revert "smb: client: fix TCP timers deadlock after rmmod"
CVE-2026-531807.527.1timers/migration: Fix livelock in tmigr_handle_remote_up()
CVE-2021-472427.526.4mptcp: fix soft lookup in subflow_error_report()
CVE-2025-219005.525.4NFSv4: Fix a deadlock when recovering state on a sillyrenamed file
CVE-2025-378025.525.3ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux128
xen3
nvidia1
red hat1
ruby-concurrency1
zephyrproject1