boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-670

Weakness type CWE-670 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26230

Monthly trend

▂▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▃▇▃█▇▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 6 · 2026-07 2 · 2026-08 7 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-534047.349.5—Apache Tomcat: Bad ornext processing in RewriteValve
CVE-2026-552769.147.2—Apache Tomcat: Logged effective web.xml is incomplete
CVE-2026-488447.541.3——
CVE-2026-201716.838.2—Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability
CVE-2026-194875.333.9—Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match resul…
CVE-2026-556245.331.6—MintyItanium Lost-Auction takes items like barrier blocks out from search GUI
CVE-2026-929325.130.7—MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSR…
CVE-2026-563075.329.0—Cap-go - Broken Cursor Pagination in /private/devices Endpoint
CVE-2026-163929.127.7—JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-563287.126.2—Capgo - Integrity Issue in Release Routing via Multiple Public Channels
CVE-2026-76566.823.7—Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Z…
CVE-2026-734687.119.6—Security Advisory 0175
CVE-2024-477457.819.2—mm: call the security_mmap_file() LSM hook in remap_file_pages()
CVE-2026-967609.818.4—Authlib library contains a signature‑verification bypass vulnerability
CVE-2026-1021105.913.3—Missing authentication on a Kiteworks appliance setup function
CVE-2022-493935.513.0—misc: fastrpc: fix list iterator in fastrpc_req_mem_unmap_impl
CVE-2026-149353.712.8—Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerpr…
CVE-2025-382915.510.1—wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash
CVE-2026-1021246.59.8—Kiteworks Core Missing Authentication for Critical Function
CVE-2026-727036.86.5—Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint via Unchec…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux4
rocq-prover3
apache2
kiteworks2
mozilla2
arista networks1
authlib1
cap-go1
capgo1
cisco1
mintyitanium1
misp1
openbsd1
red hat1
roundcube1