boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-73

Weakness type CWE-73 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2922775

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅██▂

2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 2 · 2026-03 1 · 2026-04 1 · 2026-05 12 · 2026-06 41 · 2026-07 47 · 2026-08 83 · 2026-09 79 · 2026-10 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-330538.899.7KEVInternet Shortcut Files Remote Code Execution Vulnerability
CVE-2024-434516.599.7KEVNTLM Hash Disclosure Spoofing Vulnerability
CVE-2025-240546.599.1KEVNTLM Hash Disclosure Spoofing Vulnerability
CVE-2020-16318.891.7KEVOut of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based…
CVE-2025-01117.180.0KEVPAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
CVE-2026-208726.597.4—NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-209256.597.1—NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-212493.395.9—Windows NTLM Spoofing Vulnerability
CVE-2025-713349.391.0—Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
CVE-2026-84509.184.9—HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVE-2025-684289.281.7—jsPDF has Local File Inclusion/Path Traversal vulnerability
CVE-2025-713248.774.5—Flowise - Arbitrary File Read via chatId Parameter
CVE-2023-353846.574.4—Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2025-46039.171.8—eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2024-435817.171.8—Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2024-380297.571.6—Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2026-115269.870.6—GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-…
CVE-2024-436157.168.3—Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
CVE-2025-7133810.065.9—Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-stor…
CVE-2026-776219.365.1—Vector: Arbitrary file write in the file sink via templated path (path traversal).

Most-affected vendors