Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-115
Weakness type CWE-115 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
Monthly trend
██▅▁▁
2026-06 2 · 2026-07 2 · 2026-08 1 · 2026-09 0 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-17566 | 9.4 | 50.6 | — | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incompl… |
| CVE-2026-17351 | 9.4 | 39.6 | — | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disa… |
| CVE-2026-63650 | 2.0 | 28.1 | — | — |
| CVE-2026-12491 | 4.8 | 13.8 | — | Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatc… |
| CVE-2026-42004 | 3.7 | 12.1 | — | EDNS options smuggling |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| pgadmin.org | 2 |
| openvpn | 1 |
| powerdns | 1 |
| red hat | 1 |
| vllm-project | 1 |