boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-749

Weakness type CWE-749 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
29253

Monthly trend

▃▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▅█▆▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 9 · 2026-07 6 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2010-07385.399.6KEVRed Hat JBoss
CVE-2010-14287.599.1KEVRed Hat JBoss
CVE-2018-193227.877.7KEVGIGABYTE Multiple Products
CVE-2025-266516.582.1Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2026-547535.954.2Nx: `nx graph` dev server permissive CORS policy
CVE-2026-412839.951.5
CVE-2026-536339.845.0Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CVE-2026-146204.742.2webpack-dev-server vulnerable to cross-site request forgery via internal developer endp…
CVE-2026-688239.140.8Azure Confidential Ledger Remote Code Execution Vulnerability
CVE-2025-147137.539.2
CVE-2026-454896.539.2Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-189017.337.8H3C NX15 Web API esps service.add routine
CVE-2026-554549.932.5Appsmith: Caddy admin API exposed without authentication
CVE-2026-4805610.031.2Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
CVE-2026-40517.230.1IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Aut…
CVE-2025-538279.129.4ownCloud Core: Updater has an exposed dangerous method or function
CVE-2026-448366.527.5view_component: Preview Route Can Dispatch Inherited Helper Methods
CVE-2026-120606.924.1Hepta Platforms|Heptabase - Exposed Dangerous
CVE-2026-441078.723.7Exposed Reboot via Modbus
CVE-2026-528778.323.2Streambert : Insecure Protocol Execution in open-external IPC Handler

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
nuxt2
truelockmc2
appsmithorg1
gitroomhq1
h3c1
hepta platforms1
home assistant1
home-assistant1
ibm1
lenovo1
logseq1
mediatek1
nautobot1
nrwl1