Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-122 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 658 | 564 | 2 |
▂▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▇
2025-09 0 · 2025-10 1 · 2025-11 1 · 2025-12 0 · 2026-01 10 · 2026-02 9 · 2026-03 4 · 2026-04 11 · 2026-05 63 · 2026-06 112 · 2026-07 194 · 2026-08 161
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-27997 | 9.8 | 99.7 | KEV | Fortinet FortiOS and FortiProxy SSL-VPN |
| CVE-2023-23376 | 7.8 | 95.5 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-42945 | 9.2 | 99.2 | — | NGINX ngx_http_rewrite_module vulnerability |
| CVE-2023-21690 | 9.8 | 97.9 | — | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vul… |
| CVE-2023-21689 | 9.8 | 97.9 | — | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vul… |
| CVE-2026-47291 | 9.8 | 97.5 | — | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2023-21692 | 9.8 | 97.4 | — | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vul… |
| CVE-2024-21345 | 8.8 | 97.3 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-45657 | 9.8 | 96.5 | — | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2024-30085 | 7.8 | 96.3 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-50518 | 9.8 | 95.6 | — | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-9256 | 9.2 | 95.2 | — | NGINX ngx_http_rewrite_module vulnerability |
| CVE-2026-42980 | 7.8 | 93.6 | — | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-20840 | 7.8 | 90.9 | — | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-40364 | 8.4 | 90.6 | — | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2024-30091 | 7.8 | 90.3 | — | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-42055 | 9.2 | 89.7 | — | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability |
| CVE-2026-44420 | 8.8 | 88.7 | — | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CL… |
| CVE-2023-21812 | 7.8 | 88.4 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-42533 | 9.2 | 88.2 | — | NGINX Map directive and Regex matching vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 375 |
| 42 | |
| red hat | 17 |
| adobe | 13 |
| freerdp | 12 |
| apache | 8 |
| ffmpeg | 7 |
| wireshark foundation | 7 |
| gnu | 6 |
| imagemagick | 6 |
| open asset import library | 5 |
| f5 | 4 |
| fortinet | 4 |
| freebsd | 4 |
| mediatek | 4 |