boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-732

Weakness type CWE-732 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
93901

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▅█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 11 · 2026-06 21 · 2026-07 39 · 2026-08 14

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-133744.398.4KEVFortinet FortiOS and FortiADC
CVE-2026-323155.565.7motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVE-2021-264347.856.4Visual Studio Elevation of Privilege Vulnerability
CVE-2026-105918.648.9Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
CVE-2026-736648.648.5FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
CVE-2026-534869.148.0decompress: Archive extraction can create files and links outside the target directory
CVE-2024-454977.644.9Openshift-api: openshift-controller-manager/build: build process in openshift allows ov…
CVE-2026-611559.139.1
CVE-2026-437216.536.6
CVE-2026-493408.135.8gonic has arbitrary file write in createPlaylist: any authenticated user can write play…
CVE-2026-424977.535.0Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled pat…
CVE-2026-448787.234.6Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2025-411189.134.1Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing typ…
CVE-2026-47577.232.3
CVE-2026-611869.431.9
CVE-2025-6942610.030.1Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE
CVE-2026-950810.027.2Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar
CVE-2026-240497.123.9wheel Allows Arbitrary File Permission Modification via Path Traversal
CVE-2026-635227.820.3Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-618928.719.9Weintek cMT3092X Incorrect Permission Assignment for Critical Resource

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
egor14
red hat5
acer4
oracle4
apple3
openclaw3
amd2
asus2
aws2
dräger2
gitea2
grafana2
microsoft2
watchguard2
activepieces1