boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-73

Weakness type CWE-73 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1601500

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▇█▇

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 2 · 2026-03 0 · 2026-04 1 · 2026-05 12 · 2026-06 41 · 2026-07 47 · 2026-08 43

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-208726.597.2NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-209256.596.9NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-212493.395.5Windows NTLM Spoofing Vulnerability
CVE-2025-713349.389.4Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
CVE-2025-684289.280.2jsPDF has Local File Inclusion/Path Traversal vulnerability
CVE-2023-353846.573.2Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2026-84509.170.3HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVE-2025-713248.769.9Flowise - Arbitrary File Read via chatId Parameter
CVE-2026-115269.869.3GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-…
CVE-2024-435817.168.9Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2025-46039.168.7eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2024-380297.568.7Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2024-436157.165.1Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2026-115278.662.2Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file …
CVE-2023-218007.861.8Windows Installer Elevation of Privilege Vulnerability
CVE-2025-298196.259.0Windows Admin Center in Azure Portal Information Disclosure Vulnerability
CVE-2026-658027.457.5Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2025-7133810.055.8Flowise - Arbitrary File Write to Remote Code Execution via document-store API
CVE-2025-713339.353.8Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
CVE-2026-171849.853.6IBM Db2 Mirror for i is affected by multiple vulnerabilities

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft24
ibm5
mbs5
progress5
flowise4
pnpm4
sourcecodester4
getgrav3
apache2
asus2
cisco2
docling-project2
eclipse foundation2
emagicone2
gitpython-developers2