boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-770

Weakness type CWE-770 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
7737330

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▆▇█▂

2025-11 0 · 2025-12 3 · 2026-01 7 · 2026-02 1 · 2026-03 5 · 2026-04 12 · 2026-05 36 · 2026-06 98 · 2026-07 144 · 2026-08 187 · 2026-09 207 · 2026-10 36

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-421987.590.5—pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
CVE-2026-489337.589.4——
CVE-2025-617267.582.9—Memory exhaustion in query parameter parsing in net/url
CVE-2025-97847.582.9—Undertow: undertow madeyoureset http/2 ddos vulnerability
CVE-2024-435677.582.8—Windows Hyper-V Denial of Service Vulnerability
CVE-2026-30397.582.6—BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2024-122548.778.6—Unbounded memory buffering in SelectorSocketTransport.writelines()
CVE-2026-457697.577.6—ikev2: unbounded client transform storage can lead to resource exhaustion
CVE-2025-266827.576.0—ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2026-15197.574.9—Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-454167.574.6—Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
CVE-2023-395337.573.4—libp2p nodes vulnerable to attack using large RSA keys
CVE-2023-65637.768.1—Keycloak: offline session token dos
CVE-2026-338718.767.1—Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
CVE-2026-570997.567.1—ASP.NET Core Denial of Service Vulnerability
CVE-2026-456467.566.4—OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
CVE-2026-473027.566.4—.NET Denial of Service Vulnerability
CVE-2026-497877.566.4—HTTP.sys Denial of Service Vulnerability
CVE-2026-497887.566.4—HTTP/2 Denial of Service Vulnerability
CVE-2026-505067.566.4—OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache55
red hat36
linux20
ibm18
elastic17
spring17
microsoft15
netty14
rabbitmq13
legion of the bouncy castle11
erlang10
datadog9
vllm-project9
elixir-mint8
gitlab8