boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-772

Weakness type CWE-772 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
28261

Monthly trend

▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▃█▆▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 7 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-204815.896.6KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2024-13005.462.0Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support
CVE-2026-480068.751.8Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2026-398309.147.1Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypt…
CVE-2026-480437.546.9netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener …
CVE-2026-365907.533.5
CVE-2026-646075.329.1Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to…
CVE-2026-157135.928.1Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service vi…
CVE-2026-201247.727.7Cisco IOS XE Software SNMP Denial of Service Vulnerability
CVE-2026-613876.927.6
CVE-2026-735085.326.3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
CVE-2026-732157.126.1The coturn server can end in a state where it does not accept more requests with "even-…
CVE-2026-133517.525.3net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incomi…
CVE-2026-402095.321.6Denial of service via IXFR queries
CVE-2026-416373.718.6Degradation of resolution service from improperly accounted client-terminated DNS-over-…
CVE-2026-493435.918.4Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / s…
CVE-2026-123535.317.7Rhcs: memory leak during https connection leads to denial of service
CVE-2026-135058.717.0Zeroisation of sensitive key material on garbage collection relies on finalization
CVE-2026-118113.717.0Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to reso…
CVE-2026-564445.915.0Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-time…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux4
netty4
red hat3
cisco2
nlnet labs2
apache1
bytecodealliance1
coturn1
eclipse foundation1
golang.org/x/crypto1
klever-io1
legion of the bouncy castle1
open-telemetry1
powerdns1
tanium1