boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-772

Weakness type CWE-772 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
47451

Monthly trend

▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▆▅▆█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 7 · 2026-08 10 · 2026-09 13 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-204815.896.8KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2026-31047.566.4—Memory leak in code preparing DNSSEC proofs of non-existence
CVE-2024-13005.463.5—Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support
CVE-2026-696648.759.9—httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
CVE-2026-480437.557.7—netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener …
CVE-2026-480068.756.7—Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2026-402095.351.5—Denial of service via IXFR queries
CVE-2026-713808.750.4—httpd applies no timeout while receiving a request body, parking a worker on a stalled …
CVE-2026-929838.749.7—InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch
CVE-2026-631287.548.4—RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server trans…
CVE-2026-398309.148.0—Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypt…
CVE-2026-613876.947.9——
CVE-2026-773847.547.3—libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows re…
CVE-2026-596546.846.4—Apache CloudStack: DoS caused by database connections leak
CVE-2026-365907.546.2——
CVE-2026-202508.644.0—Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense So…
CVE-2026-857185.943.0—AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial…
CVE-2026-946256.942.2—vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders
CVE-2026-201247.740.8—Cisco IOS XE Software SNMP Denial of Service Vulnerability
CVE-2026-922307.539.8—Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching

Most-affected vendors