boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-908

Weakness type CWE-908 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
161891

Monthly trend

▁▁▁▁▁▁▁▁▁▃▂▂▂▂▂▃▁▁▂▁▂▁▁▂▂▂▁▁▁▁▁▁▁▃▅█▆

2025-09 3 · 2025-10 2 · 2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 11 · 2026-06 21 · 2026-07 33 · 2026-08 22

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-57779.3100.0KEVNetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory o…
CVE-2024-120857.594.8Rsync: info leak via uninitialized stack contents
CVE-2024-435027.192.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-382577.590.7Microsoft AllJoyn API Information Disclosure Vulnerability
CVE-2026-403648.490.6Microsoft Word Remote Code Execution Vulnerability
CVE-2024-434587.776.5Windows Networking Information Disclosure Vulnerability
CVE-2023-369137.575.3Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2025-274746.574.5Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2024-382608.874.2Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2026-561909.862.7Remote Desktop Protocol Remote Code Execution Vulnerability
CVE-2026-579826.558.6Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-504977.555.9Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-585337.555.9Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-585357.555.9Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-503766.555.9Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2024-435376.554.0Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-500337.153.2slip: make slhc_remember() more robust against malicious packets
CVE-2026-457364.452.0ws: Uninitialized memory disclosure
CVE-2024-382546.251.2Windows Authentication Information Disclosure Vulnerability
CVE-2024-382565.550.9Windows Kernel-Mode Driver Information Disclosure Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux86
microsoft37
ffmpeg4
freebsd4
mozilla3
google2
libssh22
mcmilk2
red hat2
strukturag2
chan1
dell1
eclipse foundation1
f51
glibc1