boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-835

Weakness type CWE-835 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1731581

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄█▅▇▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 3 · 2026-05 11 · 2026-06 22 · 2026-07 46 · 2026-08 26 · 2026-09 38 · 2026-10 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-203538.699.4KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2026-331167.583.8—.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-428997.583.8—ASP.NET Core Denial of Service Vulnerability
CVE-2024-435126.581.2—Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2026-465227.579.4—ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-506477.566.4—Active Directory Federation Server Denial of Service Vulnerability
CVE-2026-506537.566.4—Azure Active Directory Denial of Service Vulnerability
CVE-2026-541197.566.4—Windows Active Directory Denial of Service Vulnerability
CVE-2026-48907.563.6—CVE-2026-4890
CVE-2026-441867.363.4—Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
CVE-2026-438718.762.5—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-45987.760.4——
CVE-2026-338917.558.2—Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-342827.558.0——
CVE-2026-463858.757.7—iskorotkov/avro: CPU Exhaustion in Avro Decoder
CVE-2026-503245.956.9—Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-547727.556.6—CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe …
CVE-2026-667308.754.5—facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
CVE-2026-338147.554.4—Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/in…
CVE-2026-544178.753.4—Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS

Most-affected vendors