boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-776

Weakness type CWE-776 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▃▃▁▁██▅

2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 4 · 2026-07 4 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-262787.555.1fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
CVE-2026-453048.753.9Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expan…
CVE-2026-451338.251.8Symfony: [Yaml] Harden the parser when handling untrusted input
CVE-2026-290747.546.6SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
CVE-2026-149797.532.0IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expa…
CVE-2026-735698.730.4fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
CVE-2026-457717.527.5Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVE-2026-34158.727.4XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products All…
CVE-2026-440207.526.0Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-148655.317.3XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
CVE-2026-129936.515.8Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service v…
CVE-2026-440187.11.7Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
docling-project2
naturalintelligence2
symfony2
ibm1
progress1
red hat1
signalwire1
svg1
wso21