boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-674

Weakness type CWE-674 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1951850

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▅▅▇█▂

2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 4 · 2026-04 3 · 2026-05 10 · 2026-06 32 · 2026-07 29 · 2026-08 46 · 2026-09 50 · 2026-10 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-59717.586.6—Undertow: response write hangs in case of java 17 tlsv1.3 newsessionticket
CVE-2024-81767.570.0—Libexpat: expat: improper restriction of xml entity expansion depth in libexpat
CVE-2026-494517.568.1—Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
CVE-2026-693787.566.4—Microsoft Exchange Server Denial of Service Vulnerability
CVE-2026-416065.364.5—Apache Thrift: c_glib dispatch stack overflow
CVE-2026-614837.562.5—Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow…
CVE-2022-373157.562.0——
CVE-2026-321417.561.3—flatted: Unbounded recursion DoS in parse() revive phase
CVE-2026-09905.960.6—Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
CVE-2026-420396.960.4—Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVE-2026-615518.659.6—Icinga 2: Stack overflow via deeply nested JSON objects
CVE-2026-309227.559.3—pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-934508.758.8—go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal …
CVE-2026-416738.757.7—xmldom: Denial of service via uncontrolled recursion in XML serialization
CVE-2026-662747.554.2—Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-675527.554.2—Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stacko…
CVE-2026-675907.554.2—Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-680737.554.2—Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
CVE-2026-159966.653.9—Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated ser…
CVE-2026-158306.953.8—Potential denial-of-service vulnerability via nested geometry collections

Most-affected vendors