Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-125 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1025 | 766 | 3 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▃██▆
2025-09 26 · 2025-10 13 · 2025-11 0 · 2025-12 0 · 2026-01 15 · 2026-02 5 · 2026-03 3 · 2026-04 13 · 2026-05 86 · 2026-06 239 · 2026-07 246 · 2026-08 159
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-5777 | 9.3 | 100.0 | KEV | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory o… |
| CVE-2021-4034 | 7.8 | 99.9 | KEV | Red Hat Polkit |
| CVE-2026-11645 | 8.8 | 81.0 | KEV | Google Chromium V8 |
| CVE-2024-26594 | 7.1 | 98.8 | — | ksmbd: validate mech token in session setup |
| CVE-2023-21819 | 7.5 | 98.1 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2026-8451 | 8.8 | 96.6 | — | Insufficient input validation leading to memory overread |
| CVE-2026-4891 | 5.3 | 93.0 | — | CVE-2026-4891 |
| CVE-2023-35386 | 7.8 | 92.2 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2023-3867 | 7.1 | 91.7 | — | ksmbd: fix out of bounds read in smb2_sess_setup |
| CVE-2024-43562 | 7.5 | 81.3 | — | Windows Network Address Translation (NAT) Denial of Service Vulnerability |
| CVE-2024-43565 | 7.5 | 81.3 | — | Windows Network Address Translation (NAT) Denial of Service Vulnerability |
| CVE-2024-37966 | 7.1 | 81.0 | — | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |
| CVE-2026-48132 | 8.1 | 80.6 | — | VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP |
| CVE-2026-5946 | 7.5 | 77.7 | — | Invalid handling of CLASS != IN |
| CVE-2024-21343 | 7.5 | 77.3 | — | Windows Network Address Translation (NAT) Denial of Service Vulnerability |
| CVE-2023-36905 | 7.5 | 75.8 | — | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
| CVE-2024-43534 | 6.5 | 75.3 | — | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2024-21344 | 5.9 | 75.2 | — | Windows Network Address Translation (NAT) Denial of Service Vulnerability |
| CVE-2024-37342 | 4.3 | 74.8 | — | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |
| CVE-2023-21702 | 7.5 | 74.7 | — | Windows iSCSI Service Denial of Service Vulnerability |
| Vendor | CVEs |
|---|---|
| linux | 301 |
| microsoft | 190 |
| 97 | |
| red hat | 42 |
| apple | 25 |
| zephyrproject | 16 |
| freerdp | 13 |
| imagemagick | 13 |
| adobe | 11 |
| ibm | 11 |
| mz automation | 11 |
| apache | 10 |
| strukturag | 10 |
| egor | 8 |
| gen digital | 8 |