Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 78 | 74 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▄▆█▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 0 · 2026-05 12 · 2026-06 19 · 2026-07 25 · 2026-08 15
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-0270 | 6.5 | 86.9 | — | Keystone: openstack keystone: denial of service via large http request with long tenant… |
| CVE-2026-49777 | 10.0 | 74.7 | — | WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability |
| CVE-2026-58662 | 8.7 | 64.3 | — | Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass |
| CVE-2026-2229 | 7.5 | 56.1 | — | undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s… |
| CVE-2026-3085 | 8.8 | 54.7 | — | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-8813 | 8.7 | 42.1 | — | — |
| CVE-2026-73194 | 9.1 | 41.5 | — | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated … |
| CVE-2026-75897 | 8.7 | 41.0 | — | Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards |
| CVE-2026-1528 | 7.5 | 40.1 | — | undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and c… |
| CVE-2026-54092 | 6.5 | 39.8 | — | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-55952 | 8.2 | 39.6 | — | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension |
| CVE-2026-9801 | 4.9 | 39.4 | — | Keycloak: keycloak: denial of service via malformed ldap password policy response |
| CVE-2026-39829 | 7.5 | 38.7 | — | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh |
| CVE-2026-12059 | 8.7 | 37.6 | — | Cellopoint|CelloOS - Improper Access Control |
| CVE-2026-8047 | 8.7 | 37.2 | — | Out-of-bounds Write in CODESYS Control |
| CVE-2026-59879 | 8.7 | 36.7 | — | Immutable.js `List` 32-bit trie overflow → unrecoverable DoS |
| CVE-2026-47667 | 7.5 | 35.7 | — | CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via C… |
| CVE-2026-3676 | 6.5 | 33.6 | — | There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance … |
| CVE-2026-71314 | 7.5 | 33.4 | — | Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rende… |
| CVE-2026-66374 | 8.1 | 32.2 | — | — |
| Vendor | CVEs |
|---|---|
| linux | 4 |
| ibm | 3 |
| red hat | 3 |
| zenhive | 3 |
| ads by wpquads | 2 |
| asus | 2 |
| erlang | 2 |
| gnu | 2 |
| isc | 2 |
| juniper networks | 2 |
| openbsd | 2 |
| samsung open source | 2 |
| the hdf group | 2 |
| undici | 2 |
| anh tran | 1 |