boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-829

Weakness type CWE-829 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1121082

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃██▇▇▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 7 · 2026-06 26 · 2026-07 26 · 2026-08 22 · 2026-09 23 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-07709.899.2KEVLangflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote C…
CVE-2025-324639.399.0KEVSudo Sudo
CVE-2026-598659.391.0—Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot…
CVE-2026-598677.183.4—Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-738516.182.5—Kiota: Path traversal in generated plugin manifest static_template.file reference (perc…
CVE-2026-4435910.077.7—Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target F…
CVE-2026-598649.370.1—Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-714719.067.6—Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagat…
CVE-2026-430037.565.2——
CVE-2026-676238.663.3—Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
CVE-2026-439999.960.6—vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb…
CVE-2026-861698.759.6—Axolotl before 0.19.0 Remote Code Execution via Multipack Patching
CVE-2026-52419.659.5—Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers
CVE-2026-581169.358.4—LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVE-2026-629026.557.5—.NET Information Disclosure Vulnerability
CVE-2026-571028.855.7—Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-405018.655.3—Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
CVE-2026-939938.654.1—Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout
CVE-2026-425107.253.0——
CVE-2026-761398.052.3—Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/releas…

Most-affected vendors