boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-668

Weakness type CWE-668 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
35270

Monthly trend

▂▂▁▁▂▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▂▁▄▇█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 8 · 2026-07 10 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-216268.697.0runc container breakout through process.cwd trickery and leaked fds
CVE-2026-440089.855.4vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-440099.854.1vm2: Sandbox Breakout Through Null Proto Exception
CVE-2026-454119.844.6vm2: Sandbox Breakout Using Async Generator
CVE-2026-425359.143.0Apache HTTP Server: mod_dav_fs protected directory access
CVE-2026-149609.839.4CVE-2026-14960
CVE-2026-598358.638.2
CVE-2026-450778.337.4Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
CVE-2026-560777.137.2PraisonAI - Information Disclosure via Shared MultiAgentLedger State
CVE-2026-727645.830.7n8n before 1.123.67 Module Cache Poisoning via Code Node
CVE-2024-360327.128.3Bluetooth: qca: fix info leak when fetching fw build id
CVE-2026-674278.627.0Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denyli…
CVE-2026-572317.524.0Podman: Malformed Image can trick podman run into leaking host environment variables in…
CVE-2026-471416.923.5vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2024-438817.123.3wifi: ath12k: change DMA direction while mapping reinjected packets
CVE-2026-738439.621.7OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gate…
CVE-2026-502025.921.5Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-536485.118.4FOSSBilling: Downloadable product files can be overwritten through filename collisions
CVE-2026-146115.317.0DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of r…
CVE-2021-474015.516.7ipack: ipoctal: fix stack information leak

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux6
patriksimek4
activepieces1
apache1
craftcms1
deepmyst1
dräger1
electron1
flytohub1
fortinet1
fossbilling1
lima-vm1
n8n-io1
openchoreo1
openclaw1