Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-126 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 75 | 55 | 0 |
▃▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▂▁▅█▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 3 · 2026-05 1 · 2026-06 11 · 2026-07 22 · 2026-08 16
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-26169 | 6.1 | 82.8 | — | Windows Kernel Memory Information Disclosure Vulnerability |
| CVE-2023-38172 | 7.5 | 78.8 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2024-43475 | 7.3 | 77.0 | — | Microsoft Windows Admin Center Information Disclosure Vulnerability |
| CVE-2023-21701 | 7.5 | 74.7 | — | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnera… |
| CVE-2023-21811 | 7.5 | 74.7 | — | Windows iSCSI Service Denial of Service Vulnerability |
| CVE-2023-21813 | 7.5 | 74.7 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2025-26664 | 6.5 | 74.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-26672 | 6.5 | 74.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-21203 | 6.5 | 72.3 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-26676 | 6.5 | 71.8 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2026-20846 | 7.5 | 69.0 | — | GDI+ Denial of Service Vulnerability |
| CVE-2024-38265 | 8.8 | 68.7 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2023-21720 | 5.3 | 66.2 | — | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-66312 | 8.8 | 63.1 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43595 | 6.5 | 58.8 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-25646 | 8.3 | 58.6 | — | LIBPNG has a heap buffer overflow in png_set_quantize |
| CVE-2026-26155 | 6.5 | 56.7 | — | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
| CVE-2024-38261 | 7.8 | 55.7 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-55970 | 6.9 | 54.6 | — | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() |
| CVE-2024-21340 | 4.6 | 52.2 | — | Windows Kernel Information Disclosure Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 47 |
| red hat | 5 |
| gnome | 3 |
| qualcomm | 3 |
| apache | 2 |
| fortinet | 2 |
| silabs.com | 2 |
| cisco | 1 |
| cyrusimap | 1 |
| gnu | 1 |
| neutrinolabs | 1 |
| open-telemetry | 1 |
| pnggroup | 1 |
| powerdns | 1 |
| proftpd | 1 |