boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-924

Weakness type CWE-924 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

▃▃██▃▁

2026-05 1 · 2026-06 1 · 2026-07 3 · 2026-08 3 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-398276.518.8—Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
CVE-2026-125767.512.2—DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communicati…
CVE-2026-481068.311.9—Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, e…
CVE-2026-135847.18.0—Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN commu…
CVE-2026-685542.37.7—Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attacker…
CVE-2026-851045.34.5—Brain stimulation parameters can be modified via Bluetooth in Sooma
CVE-2026-548916.32.5—Plaintext APPLICATION_DATA injected during TLS handshake delivered to client applicatio…
CVE-2019-257198.82.4—Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
CVE-2026-146814.20.0—PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
basekick-labs1
coturn1
deltaww1
dräger1
erlang1
golang.org/x/crypto1
mitsubishi electric1
sooma1