boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-805

Weakness type CWE-805 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
11110

Monthly trend

▂▂█▃▂

2026-04 1 · 2026-05 1 · 2026-06 6 · 2026-07 2 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-448937.546.9Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
CVE-2026-80919.838.8Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-125494.834.4Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
CVE-2026-120879.130.7Socket versions before 2.041 for Perl have an out-of-bounds heap read
CVE-2026-316079.823.9usbip: validate number_of_packets in usbip_pack_ret_submit()
CVE-2026-538776.320.6Heap buffer over-read in GDALRaster
CVE-2026-17678.116.1Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow lead…
CVE-2026-150283.910.6Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended …
CVE-2026-17666.15.5Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and inf…
CVE-2026-66955.54.8Gimp: gimp: remote code execution via crafted paa file
CVE-2026-530167.83.9crypto: ccp - copy IV using skcipher ivsize

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat5
linux2
djangoproject1
mozilla1
netty1
pevans1