boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-706

Weakness type CWE-706 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
42392

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 13 · 2026-09 15 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-155059.8100.0KEVIvanti MobileIron Multiple Products
CVE-2021-405399.899.9KEVZoho ManageEngine
CVE-2026-6581610.060.8—Azure Arc Elevation of Privilege Vulnerability
CVE-2026-813837.459.0—Visual Studio Code Information Disclosure Vulnerability
CVE-2026-676029.348.8—phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
CVE-2026-626858.144.2—File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-929519.443.4—vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
CVE-2026-621908.741.3—OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
CVE-2026-789859.640.9——
CVE-2026-875479.640.9——
CVE-2026-133727.240.6——
CVE-2026-876139.038.5——
CVE-2026-290368.736.4—cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
CVE-2026-876188.336.1——
CVE-2026-953348.336.1——
CVE-2026-130978.734.7—Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware unique…
CVE-2026-453066.532.8—pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory
CVE-2026-161202.131.8—nextlevelbuilder GoClaw exec_approval.go extractBin name resolution
CVE-2026-790494.328.4——
CVE-2026-570546.928.2—Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs

Most-affected vendors