boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-682

Weakness type CWE-682 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
24210

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▁▁▂▁▄▂▄▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 3 · 2026-08 6 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-714799.149.2—New API: Integer overflow in quota billing yields negative charges (self-crediting)
CVE-2025-44357.546.3—Tarfile extracts filtered members when errorlevel=0
CVE-2026-536709.341.1—PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pas…
CVE-2026-536719.341.1—PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verifi…
CVE-2026-537068.841.1—PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PAS…
CVE-2026-472477.539.2—libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pi…
CVE-2026-202708.638.3—Cisco IOS XE Software Security Hardening Release
CVE-2025-53728.838.2—Libssh: incorrect return code handling in ssh_kdf() in libssh
CVE-2026-105122.337.0—X25519 x86_64 assembly final reduction leaves non-canonical field element
CVE-2026-163639.835.7—JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-547549.635.3—Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid …
CVE-2026-334877.533.9—goxmldsig has validateSignature Loop Variable Capture Signature Bypass
CVE-2026-760438.833.3——
CVE-2026-440743.730.8—Bitwise OR of errno values
CVE-2026-867365.320.4—snipe-it before 8.7.0 Checkout Request Counter Integrity Failure
CVE-2026-203358.118.7—Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Softw…
CVE-2026-78363.118.4—hextoint macro uppercase bug
CVE-2026-107735.416.8—Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)
CVE-2026-184598.715.2—Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows…
CVE-2024-410117.811.8—drm/amdkfd: don't allow mapping the MMIO HDP page with large pages

Most-affected vendors