boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-668

Weakness type CWE-668 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
55450

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▂▂▁▁▂▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▂▁▃▆▇▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 8 · 2026-07 10 · 2026-08 10 · 2026-09 12 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-216268.697.2—runc container breakout through process.cwd trickery and leaked fds
CVE-2026-440089.858.3—vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-454119.858.3—vm2: Sandbox Breakout Using Async Generator
CVE-2026-727645.855.5—n8n before 1.123.67 Module Cache Poisoning via Code Node
CVE-2026-425359.151.9—Apache HTTP Server: mod_dav_fs protected directory access
CVE-2026-440099.851.9—vm2: Sandbox Breakout Through Null Proto Exception
CVE-2026-450778.350.1—Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
CVE-2023-217145.546.7—Microsoft Office Information Disclosure Vulnerability
CVE-2026-674278.646.4—Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denyli…
CVE-2026-545048.845.4—MCP Documentation Server: Web UI API binds to all interfaces without authentication by …
CVE-2026-545826.044.3—mport package installation can overwrite existing unmanaged or differently owned files
CVE-2026-471416.941.1—vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-738439.639.4—OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gate…
CVE-2026-9294010.038.8—vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
CVE-2026-502025.938.8—Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2023-216875.538.0—HTTP.sys Information Disclosure Vulnerability
CVE-2026-149609.837.6—CVE-2026-14960
CVE-2026-560777.136.5—PraisonAI - Information Disclosure via Shared MultiAgentLedger State
CVE-2026-572317.535.8—Podman: Malformed Image can trick podman run into leaking host environment variables in…
CVE-2026-146115.335.0—DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of r…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux6
patriksimek5
google4
microsoft2
siyuan-note2
acer1
activepieces1
andrea92931
apache1
cli1
craftcms1
darkreader1
deepmyst1
djust-org1
dräger1