boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-672

Weakness type CWE-672 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15110

Monthly trend

▃▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▃▁▃▁▁▁▁▁▁▁█▆██

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 2 · 2026-07 3 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-332789.167.6Possible arbitrary code execution during DNSSEC validation
CVE-2026-582916.145.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-563147.135.7Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
CVE-2026-684817.535.7Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
CVE-2026-527336.526.5ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork …
CVE-2026-427916.324.4OCSP responder certificate validity period not checked in public_key
CVE-2021-470697.018.0ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry
CVE-2024-579297.117.2dm array: fix releasing a faulty array block twice in dm_array_cursor_end
CVE-2026-334635.315.1Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthoriz…
CVE-2026-23798.213.6Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay i…
CVE-2026-429553.710.6Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-…
CVE-2025-396985.59.2io_uring/futex: ensure io_futex_wait() cleans up properly on failure
CVE-2026-470873.59.2
CVE-2025-382905.58.7wifi: ath12k: fix node corruption in ar->arvifs list
CVE-2026-505757.76.9BetterDesk has a replay behavior vulnerability when devices are deleted

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux4
nlnet labs2
apache1
arista networks1
capgo1
cyrusimap1
elastic1
erlang1
microsoft1
unitronix1
zcashfoundation1