boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-672

Weakness type CWE-672 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23190

Monthly trend

▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▂▁▁▁▁▁▁▁▅▃▅█▇▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 2 · 2026-07 3 · 2026-08 6 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-332789.165.3—Possible arbitrary code execution during DNSSEC validation
CVE-2026-582916.161.3—Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-552508.757.4—Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta…
CVE-2026-684817.550.0—Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
CVE-2026-616998.136.5—nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-527336.535.6—ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork …
CVE-2026-563147.134.6—Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
CVE-2026-334635.330.6—Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthoriz…
CVE-2026-447256.628.8—EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code exe…
CVE-2026-536376.527.8—Sylius: Cart FormComponent allows modification or deletion of an already-completed order
CVE-2026-427916.322.9—OCSP responder certificate validity period not checked in public_key
CVE-2026-850446.521.2——
CVE-2026-470873.519.2——
CVE-2026-953666.519.1——
CVE-2026-790104.318.0——
CVE-2021-470697.016.5—ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry
CVE-2024-579297.116.1—dm array: fix releasing a faulty array block twice in dm_array_cursor_end
CVE-2026-195388.212.8—Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
CVE-2026-23798.212.1—Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay i…
CVE-2025-382905.511.8—wifi: ath12k: fix node corruption in ar->arvifs list

Most-affected vendors