boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-681

Weakness type CWE-681 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
28280

Monthly trend

▂▂▂▃▃▄█▁

2026-03 1 · 2026-04 1 · 2026-05 1 · 2026-06 4 · 2026-07 4 · 2026-08 5 · 2026-09 12 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-46027.757.6——
CVE-2026-261788.855.7—Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVE-2026-694388.151.8—Microsoft JScript Remote Code Execution Vulnerability
CVE-2026-774128.942.4—RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
CVE-2026-539235.339.5—vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer ove…
CVE-2026-557688.738.6—GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a…
CVE-2026-551237.838.2—Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-825225.332.7—libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Truncation
CVE-2026-64264.431.3—Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds a…
CVE-2026-198795.331.1—Io.undertow/undertow: undertow: http response header integrity issue due to character t…
CVE-2026-883687.530.7——
CVE-2026-883627.525.6——
CVE-2026-504027.824.4—NTFS Elevation of Privilege Vulnerability
CVE-2026-849636.321.7—Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BS…
CVE-2026-91436.320.7—Incorrect Conversion between Numeric Types in NI grpc-device due to missing range check…
CVE-2026-883676.514.3——
CVE-2026-534666.511.4—ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
CVE-2026-241927.89.6——
CVE-2026-824578.56.9—su-exec through 0.3 Privilege Escalation via Numeric User ID
CVE-2026-751455.84.4—FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft4
mongodb3
nvidia3
red hat2
allinurl1
ffmpeg1
freebsd1
imagemagick1
libjxl1
linux1
ncopa1
ni1
rabbitmq1
samsung mobile1
vllm-project1