boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-749

Weakness type CWE-749 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
47414

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁▁▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁▁▁▁▁▁▁▁

2025-03 0 · 2025-04 2 · 2025-05 0 · 2025-06 0 · 2025-07 0 · 2025-08 0 · 2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2010-07385.399.6KEVRed Hat JBoss
CVE-2010-14287.599.1KEVRed Hat JBoss
CVE-2006-15477.599.0KEVApache Struts 1
CVE-2018-193227.877.8KEVGIGABYTE Multiple Products
CVE-2025-266516.584.3—Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2026-547535.967.2—Nx: `nx graph` dev server permissive CORS policy
CVE-2026-7752110.063.0—MaxKB: Prompt-injectable agent can lead to command execution
CVE-2026-688239.159.3—Azure Confidential Ledger Remote Code Execution Vulnerability
CVE-2026-412839.958.8——
CVE-2026-536339.858.1—Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CVE-2026-454896.557.6—Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-189017.356.7—H3C NX15 Web API esps service.add routine
CVE-2025-538279.147.6—ownCloud Core: Updater has an exposed dangerous method or function
CVE-2026-554549.947.0—Appsmith: Caddy admin API exposed without authentication
CVE-2026-891398.745.8—Temporal Server worker deployment compute provider executes a caller-supplied command o…
CVE-2026-441078.744.6—Exposed Reboot via Modbus
CVE-2026-4805610.044.3—Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
CVE-2026-146204.742.2—webpack-dev-server vulnerable to cross-site request forgery via internal developer endp…
CVE-2026-40517.240.6—IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Aut…
CVE-2026-447987.140.5—Nautobot: GitRepository.current_head field should not be writable through REST API

Most-affected vendors