Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1284
Weakness type CWE-1284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 136 | 130 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃▅▆▆█▂
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 1 · 2026-05 12 · 2026-06 19 · 2026-07 25 · 2026-08 26 · 2026-09 38 · 2026-10 6
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-0270 | 6.5 | 87.6 | — | Keystone: openstack keystone: denial of service via large http request with long tenant… |
| CVE-2026-49777 | 10.0 | 80.3 | — | WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability |
| CVE-2026-94450 | 8.7 | 79.5 | — | Potential denial of service when configured to send Retry packets in s2n-quic |
| CVE-2026-3085 | 8.8 | 67.4 | — | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-58662 | 8.7 | 63.9 | — | Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass |
| CVE-2025-3511 | 7.5 | 58.5 | — | — |
| CVE-2026-9801 | 4.9 | 58.1 | — | Keycloak: keycloak: denial of service via malformed ldap password policy response |
| CVE-2026-2229 | 7.5 | 57.5 | — | undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s… |
| CVE-2026-34756 | 6.5 | 53.9 | — | vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in O… |
| CVE-2026-50285 | 7.5 | 53.0 | — | Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback |
| CVE-2026-75897 | 8.7 | 52.1 | — | Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards |
| CVE-2026-59696 | 6.9 | 51.9 | — | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-70405 | 6.3 | 51.9 | — | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-59879 | 8.7 | 50.1 | — | Immutable.js `List` 32-bit trie overflow → unrecoverable DoS |
| CVE-2026-71314 | 7.5 | 49.7 | — | Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rende… |
| CVE-2026-87962 | 8.7 | 48.4 | — | t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDige… |
| CVE-2026-93749 | 8.7 | 48.3 | — | source-map-js through 1.2.1 Event Loop Denial of Service |
| CVE-2026-59252 | 8.2 | 48.3 | — | Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain |
| CVE-2026-19566 | 7.5 | 48.4 | — | Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set … |
| CVE-2026-49218 | 7.5 | 48.3 | — | ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| erlang | 6 |
| zenhive | 6 |
| apache | 5 |
| red hat | 5 |
| ibm | 4 |
| linux | 4 |
| eclipse foundation | 3 |
| watchguard | 3 |
| ads by wpquads | 2 |
| ash-project | 2 |
| asus | 2 |
| aws | 2 |
| cisco | 2 |
| gnu | 2 |
| isc | 2 |