boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-704

Weakness type CWE-704 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
25230

Monthly trend

▂▁▁▁▁▂▁▁▁▁▁▁▁▃▄▅█▇▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 3 · 2026-07 4 · 2026-08 7 · 2026-09 6 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-158269.890.0—User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusi…
CVE-2026-443246.551.4—free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf…
CVE-2026-598717.549.1—node-tar: Process crash via PAX numeric path type confusion
CVE-2026-456857.548.5—OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVE-2026-465977.547.9—Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-550767.447.4—Coder's OIDC email_verified type coercion bypass enables account takeover via unverifie…
CVE-2025-516787.547.3——
CVE-2026-186755.344.7—Kong Mesh: control plane denial of service via a malformed dataplane token with a non-s…
CVE-2026-734295.341.1—Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
CVE-2026-502786.537.1—iccDEV: CIccEmbedIO::Read8() size_t underflow
CVE-2026-481407.136.5—Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream
CVE-2026-537986.934.9—rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
CVE-2026-100806.534.1—Boards plugin panics on WebSocket command with non-string field types
CVE-2026-202498.631.8—Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense So…
CVE-2026-588229.829.9——
CVE-2026-286098.828.8——
CVE-2026-863484.327.4—MS Calendar plugin: unrecovered handler panics from malformed post-action requests coul…
CVE-2026-503377.824.4—Windows Notification Elevation of Privilege Vulnerability
CVE-2026-695857.824.4—Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2025-398807.823.1—libceph: fix invalid accesses to ceph_connection_v1_info

Most-affected vendors