boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-776

Weakness type CWE-776 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
19190

Monthly trend

▂▂▁▂▇▇▅█▁

2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 4 · 2026-07 4 · 2026-08 3 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-262787.560.5—fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
CVE-2026-290747.560.5—SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
CVE-2026-416738.757.7—xmldom: Denial of service via uncontrolled recursion in XML serialization
CVE-2026-453048.750.9—Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expan…
CVE-2026-451338.248.4—Symfony: [Yaml] Harden the parser when handling untrusted input
CVE-2026-440207.546.9—Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-149797.544.0—IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expa…
CVE-2026-786818.742.2—NLTK before 3.10.3 Entity Expansion DoS via ElementTree
CVE-2026-129936.542.1—Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service v…
CVE-2026-735698.741.1—fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
CVE-2026-457717.539.8—Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVE-2026-34158.739.7—XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products All…
CVE-2026-540777.136.6—ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
CVE-2026-148655.335.3—XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
CVE-2023-460355.927.9——
CVE-2026-920016.126.3—Apache Sling XSS: Missing parser resource limits
CVE-2026-582342.224.9—Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
CVE-2026-161805.711.9—IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerabl…
CVE-2026-440187.14.7—Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
docling-project2
ibm2
naturalintelligence2
symfony2
apache1
arcadedata1
com.arcadedb1
fnando1
nltk1
progress1
red hat1
sap_se1
signalwire1
svg1
wso21