boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-80

Weakness type CWE-80 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
72683

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▅▆█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 17 · 2026-07 11 · 2026-08 14 · 2026-09 20 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-139656.399.5KEVRoundcube Webmail
CVE-2018-199536.198.1KEVQNAP Network Attached Storage (NAS)
CVE-2018-199435.497.6KEVQNAP Network Attached Storage (NAS)
CVE-2026-502296.190.4—Apache Tomcat: XSS in number guess example
CVE-2026-732376.154.9—Apache Allura: XSS in markdown pipeline
CVE-2026-732386.154.9—Apache Allura: XSS in code display
CVE-2026-758726.953.0—HTML Injection in MailerUp double opt-in verification email
CVE-2026-327736.150.7—Apache Spark: XSS Vulnerability in Spark Web 3.5.4
CVE-2026-528165.450.6—Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs le…
CVE-2026-527746.149.7—Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
CVE-2026-527736.146.4—Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.p…
CVE-2026-528548.645.6—mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser fun…
CVE-2026-489106.544.6—Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
CVE-2026-527417.543.3—GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages
CVE-2026-598558.642.8—SiYuan: Store XSS To Rce via Asset.render
CVE-2026-658415.342.8—Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-htm…
CVE-2026-340335.442.1—Apache Answer: HTML Content Injection in Email
CVE-2025-621985.441.0—Apache Atlas: Stored XSS in Create Entity page
CVE-2026-416117.841.0—Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-732208.539.5—CVAT: Stored XSS via annotation guides in audio tasks

Most-affected vendors