boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-835

Weakness type CWE-835 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
107931

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅█▃

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 9 · 2026-06 22 · 2026-07 44 · 2026-08 15

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-203538.699.3KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2026-48907.593.8CVE-2026-4890
CVE-2026-428997.582.9ASP.NET Core Denial of Service Vulnerability
CVE-2026-331167.580.6.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2024-435126.580.4Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2026-465227.577.4ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-438718.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-506477.562.3Active Directory Federation Server Denial of Service Vulnerability
CVE-2026-551998.257.5libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
CVE-2026-541197.554.3Windows Active Directory Denial of Service Vulnerability
CVE-2026-503245.953.2Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-506537.553.1Azure Active Directory Denial of Service Vulnerability
CVE-2026-470668.752.2Infinite loop in Alt-Svc header parser in hackney
CVE-2024-362885.552.1SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
CVE-2025-713198.751.4image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
CVE-2026-599337.550.0PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2025-81947.546.6Tarfile infinite loop during parsing with negative member offset
CVE-2026-667308.745.9facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
CVE-2026-441867.345.3Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
CVE-2026-113527.545.0QUIC zero-length UDP datagrams busy-loop

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux22
red hat8
microsoft7
ibm5
zephyrproject5
imagemagick4
py-pdf4
image-size3
apache2
codechild2
mermaid-js2
nanoid_project2
101arrowz1
@fastify/busboy1
benoitc1