boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-770

Weakness type CWE-770 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
4474140

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▇

2025-09 5 · 2025-10 1 · 2025-11 0 · 2025-12 2 · 2026-01 7 · 2026-02 1 · 2026-03 3 · 2026-04 7 · 2026-05 34 · 2026-06 99 · 2026-07 144 · 2026-08 119

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-489337.588.9
CVE-2026-421987.587.4pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
CVE-2026-455917.582.9ASP.NET Core Denial of Service Vulnerability
CVE-2025-97847.582.1Undertow: undertow madeyoureset http/2 ddos vulnerability
CVE-2024-435677.582.0Windows Hyper-V Denial of Service Vulnerability
CVE-2025-617267.578.6Memory exhaustion in query parameter parsing in net/url
CVE-2026-451126.978.5Apache Thrift: Unbounded Read Leading to Denial of Service
CVE-2024-122548.777.8Unbounded memory buffering in SelectorSocketTransport.writelines()
CVE-2026-15197.573.8Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2025-266827.572.9ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2026-541137.563.7Remote Procedure Call Denial of Service Vulnerability
CVE-2026-338718.763.7Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
CVE-2026-559688.763.0Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVE-2026-583898.763.0Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVE-2026-452925.363.0opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
CVE-2026-30397.561.5BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-473027.561.0.NET Denial of Service Vulnerability
CVE-2023-53797.560.6Undertow: ajp request closes connection exceeding maxrequestsize
CVE-2026-561707.560.3ASP.NET Core Denial of Service Vulnerability
CVE-2026-425877.559.8Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snapp…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache22
linux20
red hat16
microsoft13
netty13
elastic11
ibm11
spring8
erlang6
go standard library6
legion of the bouncy castle6
elixir-mint5
gitlab5
open-telemetry5
scriban5