boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-732

Weakness type CWE-732 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1541473

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▃▅█▆█▁

2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 2 · 2026-04 4 · 2026-05 11 · 2026-06 21 · 2026-07 39 · 2026-08 28 · 2026-09 38 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2019-157527.898.8KEVDocker Desktop Community Edition
CVE-2018-133744.398.5KEVFortinet FortiOS and FortiADC
CVE-2022-229607.898.4KEVVMware Multiple Products
CVE-2021-270707.390.5—Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2026-323155.586.7—motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVE-2021-264347.857.8—Visual Studio Elevation of Privilege Vulnerability
CVE-2026-858877.756.4—M365 Copilot Information Disclosure Vulnerability
CVE-2026-534869.153.3—decompress: Archive extraction can create files and links outside the target directory
CVE-2026-105918.651.3—Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
CVE-2026-195839.946.9—Velociraptor Required Permissions bypass by using client monitoring queries
CVE-2026-448787.246.8—Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2026-47577.245.2——
CVE-2024-454977.644.2—Openshift-api: openshift-controller-manager/build: build process in openshift allows ov…
CVE-2026-950810.043.8—Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar
CVE-2026-736648.641.1—FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
CVE-2026-618928.741.1—Weintek cMT3092X Incorrect Permission Assignment for Critical Resource
CVE-2026-611559.140.3——
CVE-2026-424977.538.5—Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled pat…
CVE-2025-128016.538.5—Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
CVE-2026-826972.937.9—sambitraj Student-Management-System session_start cookie httponly flag

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
egor14
red hat9
dell6
splunk6
acer4
apple4
microsoft4
oracle4
openclaw3
amd2
apache http server project2
asus2
aws2
dräger2
duplicati2