boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-825

Weakness type CWE-825 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
48410

Monthly trend

▂▁▁▁▁▂▁▁▁▁▁▄█▂▂▂▁

2025-11 4 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 9 · 2026-06 20 · 2026-07 4 · 2026-08 3 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-454478.890.2—Heap Use-After-Free in the PKCS7_verify() Function
CVE-2026-67229.569.3—Use-After-Free in SOAP using Apache map
CVE-2025-497949.156.2—Libxml: heap use after free (uaf) leads to denial of service (dos)
CVE-2026-61009.153.7—Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after r…
CVE-2026-444228.849.6—FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion
CVE-2025-497957.546.4—Libxml: null pointer dereference leads to denial of service (dos)
CVE-2026-585928.944.0—Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssem…
CVE-2026-530069.842.7—ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-529249.842.6—sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-123288.138.9—Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140…
CVE-2026-459729.838.2—smb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-88547.537.7—IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-574351.737.7—Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::A…
CVE-2026-531759.836.9—inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
CVE-2026-461258.836.2—wifi: mac80211: remove station if connection prep fails
CVE-2026-659705.334.5—OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_nativ…
CVE-2026-772207.134.2—PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
CVE-2026-465236.233.7—ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-781235.933.2——
CVE-2026-122918.829.8—Use-after-free in the Networking: HTTP component

Most-affected vendors