boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-824

Weakness type CWE-824 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26182

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▃▃▅▁▁▁▁▁▁▁▁▁▁▃▁▁▁▅▁▃▃▆▆▅▃█▃

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 3 · 2026-06 3 · 2026-07 2 · 2026-08 1 · 2026-09 4 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-219717.899.0KEVWindows Runtime Remote Code Execution Vulnerability
CVE-2015-17708.898.4KEVMicrosoft Office
CVE-2026-21007.566.0—P11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-672818.752.5—Unauthenticated file read in Mikrotik RouterOS
CVE-2026-429598.752.1—Crash during DNSSEC validation of malicious content
CVE-2026-457367.550.5—ws: Uninitialized memory disclosure
CVE-2026-163539.841.9—Invalid pointer in the DOM: Bindings (WebIDL) component
CVE-2026-394588.737.7—BIG-IP DNS Cache vulnerability
CVE-2026-1007889.836.2—Invalid pointer in the JavaScript: WebAssembly component
CVE-2026-660818.734.6—Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-version…
CVE-2026-549200.027.0—OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil…
CVE-2026-479087.819.9—Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)
CVE-2026-164097.519.4—Invalid pointer in the Security: PSM component
CVE-2024-468447.815.7—um: line: always fill *error_out in setup_one_line()
CVE-2026-273005.515.7—Adobe Framemaker | Access of Uninitialized Pointer (CWE-824)
CVE-2026-212757.814.5—InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
CVE-2026-212767.814.5—InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
CVE-2024-267997.013.8—ASoC: qcom: Fix uninitialized pointer dmactl
CVE-2024-500887.810.7—btrfs: fix uninitialized pointer free in add_inode_ref()
CVE-2024-500875.510.7—btrfs: fix uninitialized pointer free on read_alloc_one_name() error

Most-affected vendors