boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-755

Weakness type CWE-755 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
52413

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▁▂▂▁▁▁▂▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▆▂█▄

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 5 · 2026-07 10 · 2026-08 2 · 2026-09 13 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2017-56389.8100.0KEVApache Struts
CVE-2020-72479.899.9KEVOpenBSD OpenSMTPD
CVE-2021-380038.898.5KEVGoogle Chromium V8
CVE-2026-236667.570.1—.NET Framework Denial of Service Vulnerability
CVE-2020-10716.862.4—Windows Remote Access Common Dialog Elevation of Privilege Vulnerability
CVE-2026-890258.754.1—Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
CVE-2026-534599.353.7—Bambuddy's authentication fails open on database errors, allowing unauthenticated acces…
CVE-2024-265845.553.0—net: tls: handle backlogging of crypto requests
CVE-2026-546327.552.2—SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media s…
CVE-2026-443197.549.6—free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co…
CVE-2026-443257.549.6—free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Ref…
CVE-2026-591626.949.6—Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVE-2024-65948.748.8—WatchGuard Firebox Single Sign-On Client Denial-of-Service
CVE-2026-95167.547.7—Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pr…
CVE-2026-528567.547.3—Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser…
CVE-2026-815157.547.3—Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry f…
CVE-2026-815167.547.3—Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (…
CVE-2026-547756.546.8—CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),…
CVE-2026-599275.342.8—Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `…
CVE-2026-599526.942.4—Valibot: record() issue paths can make flatten() throw for inherited Object property names

Most-affected vendors