Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1285 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 9 | 0 |
▃▁▁▁▁▆▁█▆▁▆
2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 2 · 2026-07 0 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-32285 | 7.5 | 52.1 | — | Denial of service in github.com/buger/jsonparser |
| CVE-2026-32286 | 7.5 | 48.4 | — | Denial of service in github.com/jackc/pgproto3/v2 |
| CVE-2026-44004 | 7.5 | 35.1 | — | vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass) |
| CVE-2025-8291 | 4.3 | 28.5 | — | ZIP64 End of Central Directory (EOCD) Locator record offset not checked |
| CVE-2026-45352 | 7.5 | 25.7 | — | cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding |
| CVE-2026-9100 | 6.0 | 22.1 | — | Heap memory out of bounds read and crash in C Driver legacy GridFS file reader |
| CVE-2026-12681 | 8.9 | 9.2 | — | — |
| CVE-2026-18485 | 8.5 | 1.7 | — | Local Privilege Escalation in NI-PAL |
| CVE-2026-14479 | 5.5 | 1.7 | — | Denial of Service in Autodesk Installer IPC Channel |
| CVE-2026-8036 | 8.4 | 1.3 | — | Local privilege escalation in NI-PAL |
| Vendor | CVEs |
|---|---|
| ni | 2 |
| autodesk | 1 |
| github.com/buger/jsonparser | 1 |
| github.com/jackc/pgproto3/v2 | 1 |
| 1 | |
| mongodb | 1 |
| patriksimek | 1 |
| python software foundation | 1 |
| yhirose | 1 |