boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-833

Weakness type CWE-833 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
860

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▅▁▅█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 0 · 2026-08 1 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-445797.553.8—Next.js: Denial of Service via connection exhaustion in applications using Cache Compon…
CVE-2024-84475.950.9—Narayana: deadlock via multiple join requests sent to lra coordinator
CVE-2026-463527.538.5—Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock
CVE-2026-706167.124.7—boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
CVE-2026-106475.39.0—Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
CVE-2026-777986.58.7—Velociraptor Authenticated Denial of Service
CVE-2024-06395.56.5—Kernel: potential deadlock on &net->sctp.addr_wq_lock leading to dos
CVE-2026-473345.50.9—Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat2
boringproxy1
canonical1
oisf1
rapid71
vercel1
zephyrproject1