boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-834

Weakness type CWE-834 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
17160

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▄█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 1 · 2026-08 3 · 2026-09 8 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-646418.257.0—Next.js: Denial of Service in App Router using Server Actions
CVE-2026-773578.742.9—Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker th…
CVE-2026-596448.740.3—MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
CVE-2026-456807.539.4—OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
CVE-2026-164977.538.9——
CVE-2026-911378.734.7—Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements
CVE-2026-818726.330.1—OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
CVE-2026-534936.927.2—Containerd has image-pull DoS via crafted OCI index graph amplification
CVE-2026-877218.723.1—Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit C…
CVE-2026-773996.522.0—icalendar: Denial of service via unbounded VALARM REPEAT expansion
CVE-2026-501718.215.7—Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2024-420715.511.0—ionic: use dev_consume_skb_any outside of napi
CVE-2026-481565.16.0—pypdf: Possible long runtimes for zero-only width values in cross-reference streams
CVE-2026-818805.52.8—radare2: Uncontrolled resource consumption in radare2 PEF loader
CVE-2026-843104.82.5—pypdf: Possible long runtimes/large memory usage when retrieving outlines
CVE-2026-843114.82.5—pypdf: Possible long runtimes/large memory usage when extracting XForm objects
CVE-2026-718524.82.0—pypdf: Possible long runtimes/large memory usage for large CID font width ranges

Most-affected vendors