boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-789

Weakness type CWE-789 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
82810

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▇█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 9 · 2026-06 14 · 2026-07 26 · 2026-08 31

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-499757.597.9Apache HTTP Server: mod_http2 denial of service
CVE-2024-434847.586.0.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-539177.565.1Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U…
CVE-2026-667338.756.5Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
CVE-2026-403787.554.3Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-421547.554.2Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-438685.350.6Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-424407.546.2Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVE-2026-653158.744.8Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser
CVE-2026-446307.544.4Apache IoTDB: RPC service denial of service via unchecked Thrift string length
CVE-2026-507347.543.3Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWi…
CVE-2026-539167.543.3Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in…
CVE-2026-598446.542.3Libssh: libssh: denial of service via oversized sftp read length
CVE-2026-614857.542.1Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
CVE-2026-153376.942.1Potential denial-of-service vulnerability in check_for_language()
CVE-2026-675517.540.4Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pr…
CVE-2026-675897.540.4Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-aut…
CVE-2026-95387.537.5Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker control…
CVE-2026-759358.736.9Memory-amplification denial of service via declared-length preallocation in Amazon ion-…
CVE-2026-155677.536.5Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache12
legion of the bouncy castle6
elastic5
python-pillow5
red hat3
h2o2
m2team2
microsoft2
open-telemetry2
open62541 project / o6 automation2
aizuda1
allinurl1
amazon ion1
anthropics1
aquasecurity1