Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-121 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 427 | 411 | 3 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▇▆
2025-09 0 · 2025-10 0 · 2025-11 2 · 2025-12 1 · 2026-01 1 · 2026-02 3 · 2026-03 1 · 2026-04 3 · 2026-05 73 · 2026-06 128 · 2026-07 105 · 2026-08 97
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-22457 | 9.8 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and ZTA Gateways |
| CVE-2025-0282 | 9.0 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and ZTA Gateways |
| CVE-2021-27137 | 8.1 | 96.7 | KEV | DD-WRT DD-WRT |
| CVE-2026-41089 | 9.8 | 99.6 | — | Windows Netlogon Remote Code Execution Vulnerability |
| CVE-2026-0826 | 9.2 | 97.7 | — | Poly Voice – Possible Remote Control of Certain Poly Devices |
| CVE-2026-10187 | 8.9 | 93.9 | — | Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow |
| CVE-2026-11499 | 9.3 | 93.3 | — | Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow |
| CVE-2026-11498 | 8.7 | 89.1 | — | Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow |
| CVE-2026-10179 | 7.4 | 87.1 | — | TRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflow |
| CVE-2024-30083 | 7.5 | 83.4 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
| CVE-2026-73522 | 8.7 | 82.4 | — | COVESA Open1722 0.9.2 Stack Buffer Overflow via avtp_to_can() in acf-can-listener |
| CVE-2026-56766 | 8.6 | 79.0 | — | Hydra - Stack Buffer Overflow in NTLM Authentication Handler |
| CVE-2026-50387 | 7.8 | 78.3 | — | Windows GDI Elevation of Privilege Vulnerability |
| CVE-2026-32203 | 7.5 | 78.0 | — | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43549 | 8.8 | 68.6 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2025-27481 | 8.8 | 64.8 | — | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2026-45648 | 8.8 | 63.7 | — | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-44815 | 9.8 | 63.1 | — | DHCP Client Service Remote Code Execution Vulnerability |
| CVE-2026-50304 | 7.5 | 62.3 | — | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50355 | 7.5 | 62.3 | — | Windows Active Directory Federation Services Denial of Service Vulnerability |