boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-822

Weakness type CWE-822 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
102825

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▁▁▁▁▁▂▁▁▁▁▂▁▁▁▃▂▁▃▂▂▄▅█▂

2025-11 0 · 2025-12 0 · 2026-01 9 · 2026-02 2 · 2026-03 0 · 2026-04 8 · 2026-05 3 · 2026-06 5 · 2026-07 11 · 2026-08 14 · 2026-09 28 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-213387.899.1KEVWindows Kernel Elevation of Privilege Vulnerability
CVE-2024-352507.897.9KEVWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2023-293608.497.6KEVMicrosoft Streaming Service Elevation of Privilege Vulnerability
CVE-2023-360337.895.8KEVWindows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-249907.893.5KEVWindows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2024-213467.890.5—Win32k Elevation of Privilege Vulnerability
CVE-2024-300907.079.8—Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2024-373398.875.3—Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
CVE-2024-373408.875.3—Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
CVE-2026-504247.566.4—Windows Domain Controller Denial of Service Vulnerability
CVE-2026-212507.864.6—Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-729386.559.0—Microsoft Office PowerPoint Information Disclosure Vulnerability
CVE-2026-729566.559.0—Microsoft Office PowerPoint Information Disclosure Vulnerability
CVE-2025-298127.858.8—DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-331208.858.7—Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-695695.757.0—Windows Print Spooler Components Denial of Service Vulnerability
CVE-2024-435297.356.1—Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2025-277477.855.9—Microsoft Word Remote Code Execution Vulnerability
CVE-2026-481379.355.1—Untrusted pointer dereference in NI grpc-device sideband streaming API
CVE-2026-697178.854.0—Windows Group Policy Elevation of Privilege Vulnerability

Most-affected vendors