boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-755

Weakness type CWE-755 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
31240

Monthly trend

▂▁▁▂▁▂▂▁▁▁▂▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▅█▂

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 6 · 2026-07 10 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-236667.568.8.NET Framework Denial of Service Vulnerability
CVE-2024-265845.552.0net: tls: handle backlogging of crypto requests
CVE-2024-65948.747.6WatchGuard Firebox Single Sign-On Client Denial-of-Service
CVE-2026-403718.847.5Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-599526.942.3Valibot: record() issue paths can make flatten() throw for inherited Object property names
CVE-2022-486735.541.0net/smc: Fix possible access to freed memory in link clear
CVE-2026-449027.537.9opentelemetry-js: Prometheus exporter process crash via malformed HTTP request
CVE-2026-427926.336.9epmd permanent DoS via EMFILE on accept(2) in erts
CVE-2026-443197.533.8free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co…
CVE-2026-443257.532.7free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Ref…
CVE-2026-591626.932.3Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVE-2026-458196.630.4
CVE-2026-492358.730.0Routinator crashes on specifically crafted RRDP XML files
CVE-2026-95167.529.3Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pr…
CVE-2026-599275.328.4Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `…
CVE-2026-492328.727.3Routinator exits when accepting an incoming HTTP or RTR connection fails
CVE-2026-547756.526.6CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),…
CVE-2026-485243.726.6PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values …
CVE-2026-528567.526.5Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser…
CVE-2024-500015.525.6net/mlx5: Fix error path in multi-packet WQE transmit

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux5
free5gc2
microsoft2
nlnet labs2
red hat2
@opentelemetry1
coredns1
corewcf1
erlang1
huawei1
imagemagick1
jpadilla1
kerberosmansour1
lepture1
nimiq1