boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-789

Weakness type CWE-789 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1321300

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▆▇█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 9 · 2026-06 14 · 2026-07 26 · 2026-08 33 · 2026-09 37 · 2026-10 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-499757.590.6—Apache HTTP Server: mod_http2 denial of service
CVE-2024-434847.586.7—.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-667338.774.3—Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
CVE-2026-438685.367.1—Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-403787.566.4—Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-424407.563.5—Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVE-2026-421547.558.1—Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-653158.755.4—Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser
CVE-2026-662737.554.2—Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-aut…
CVE-2026-675517.554.2—Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pr…
CVE-2026-675897.554.2—Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-aut…
CVE-2026-854428.753.9—MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation
CVE-2026-554076.353.5—Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Alloca…
CVE-2026-917528.753.0—GNU libextractor before 1.15 Stack Overflow via OLE2
CVE-2026-507347.553.0—Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWi…
CVE-2026-539167.553.0—Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in…
CVE-2026-539177.553.0—Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U…
CVE-2026-672117.553.0—Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
CVE-2026-692198.752.5—RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via un…
CVE-2026-551497.552.2—Vouch Proxy: Unbounded Multipart Cookie Allocation DoS

Most-affected vendors