Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-125
Weakness type CWE-125 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1611 | 1328 | 19 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅▅█▁
2025-11 0 · 2025-12 1 · 2026-01 19 · 2026-02 23 · 2026-03 14 · 2026-04 23 · 2026-05 92 · 2026-06 238 · 2026-07 266 · 2026-08 234 · 2026-09 415 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2014-0160 | 7.5 | 100.0 | KEV | OpenSSL OpenSSL |
| CVE-2025-5777 | 9.3 | 100.0 | KEV | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory o… |
| CVE-2021-4034 | 7.8 | 99.9 | KEV | Red Hat Polkit |
| CVE-2016-1646 | 8.8 | 98.8 | KEV | Google Chromium V8 |
| CVE-2017-5030 | 8.8 | 98.6 | KEV | Google Chromium V8 |
| CVE-2016-4523 | 7.5 | 98.2 | KEV | Trihedral VTScada (formerly VTS) |
| CVE-2020-11899 | 5.4 | 97.2 | KEV | Treck TCP/IP stack IPv6 |
| CVE-2023-42916 | 6.5 | 97.1 | KEV | Apple Multiple Products |
| CVE-2023-28204 | 6.5 | 96.5 | KEV | Apple Multiple Products |
| CVE-2023-36424 | 7.8 | 96.0 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2025-5419 | 8.8 | 94.5 | KEV | Google Chromium V8 |
| CVE-2026-3055 | 9.3 | 90.3 | KEV | Insufficient input validation leading to memory overread |
| CVE-2024-0519 | 8.8 | 89.7 | KEV | Google Chromium V8 |
| CVE-2026-11645 | 8.8 | 84.3 | KEV | Google Chromium V8 |
| CVE-2025-24991 | 5.5 | 79.8 | KEV | Windows NTFS Information Disclosure Vulnerability |
| CVE-2025-22226 | 7.1 | 77.4 | KEV | VMware ESXi, Workstation, and Fusion |
| CVE-2024-53150 | 7.1 | 70.6 | KEV | ALSA: usb-audio: Fix out of bounds reads when finding clock sources |
| CVE-2022-22674 | 5.5 | 65.3 | KEV | Apple macOS |
| CVE-2021-25487 | 7.3 | 48.6 | KEV | Samsung Mobile Devices |
| CVE-2024-26594 | 7.1 | 98.9 | — | ksmbd: validate mech token in session setup |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 347 |
| linux | 326 |
| 126 | |
| red hat | 76 |
| adobe | 52 |
| apple | 51 |
| ibm | 30 |
| zephyrproject | 25 |
| freerdp | 18 |
| nvidia | 18 |
| academysoftwarefoundation | 14 |
| eclipse foundation | 13 |
| imagemagick | 13 |
| strukturag | 13 |
| mz automation | 11 |