boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-829

Weakness type CWE-829 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
82791

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃██▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 7 · 2026-06 26 · 2026-07 26 · 2026-08 19

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-07709.899.0KEVLangflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote C…
CVE-2026-598659.387.1Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot…
CVE-2026-598677.178.3Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-738516.171.8Kiota: Path traversal in generated plugin manifest static_template.file reference (perc…
CVE-2026-714719.071.3Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagat…
CVE-2026-598649.367.6Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-4435910.060.2Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target F…
CVE-2026-439999.959.3vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb…
CVE-2026-430037.554.5
CVE-2026-571028.852.7Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-629026.552.5.NET Information Disclosure Vulnerability
CVE-2024-300928.049.2Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-581169.348.1LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVE-2026-52419.643.5Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers
CVE-2026-465298.442.5PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
CVE-2026-676238.642.5Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
CVE-2026-184088.842.4PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary c…
CVE-2026-446888.441.2
CVE-2026-465808.441.2
CVE-2026-64648.140.3PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft9
jetbrains8
eclipse foundation5
pnpm3
vim3
concrete cms2
docker2
duck-organization2
mervinpraison2
openclaw2
red hat2
synology2
axllent1
cdeust1
cherryhq1