Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-124
Weakness type CWE-124 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 7 | 1 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▃▁▁▃▆█▁▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 2 · 2026-08 3 · 2026-09 0 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2015-2426 | 8.8 | 99.7 | KEV | Microsoft Windows |
| CVE-2026-40013 | 4.3 | 57.3 | — | — |
| CVE-2026-44631 | 9.8 | 53.2 | — | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow |
| CVE-2025-4373 | 4.8 | 48.7 | — | Glib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar |
| CVE-2026-0966 | 8.2 | 45.9 | — | Libssh: libssh: denial of service via zero-length input in ssh_get_hexa() |
| CVE-2026-16439 | 5.8 | 35.0 | — | Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow |
| CVE-2026-26199 | 5.9 | 26.5 | — | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero |
| CVE-2026-71969 | 8.4 | 7.1 | — | OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations |
| CVE-2026-73075 | 4.6 | 5.5 | — | Vim: Out-of-bounds Access in Popup Opacity Handling |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 2 |
| apache | 1 |
| eclipse foundation | 1 |
| hdfgroup | 1 |
| op-tee | 1 |
| open-xchange | 1 |
| vim | 1 |