Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1286 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 19 | 0 |
▂▂▁▂█▂▃
2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 11 · 2026-07 1 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21527 | 6.5 | 94.1 | — | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-42579 | 9.1 | 60.3 | — | Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) |
| CVE-2026-25679 | 7.5 | 51.4 | — | Incorrect parsing of IPv6 host literals in net/url |
| CVE-2026-48059 | 8.7 | 47.5 | — | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M… |
| CVE-2025-8873 | 8.7 | 31.9 | — | Arista EOS Dataplane Denial of Service via Malformed IPsec Packet |
| CVE-2026-72916 | 6.3 | 29.2 | — | Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses |
| CVE-2026-50131 | 8.6 | 28.3 | — | Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl a… |
| CVE-2026-57026 | 8.7 | 26.1 | — | Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP i… |
| CVE-2026-0931 | 6.9 | 15.6 | — | Denial-of-service vulnerability in M-Files Server |
| CVE-2021-4479 | 6.3 | 15.6 | — | Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface |
| CVE-2019-25723 | 6.3 | 14.9 | — | Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface |
| CVE-2019-25720 | 7.1 | 10.1 | — | Dräger SC Monitoring Devices DoS via Malformed Network Packet |
| CVE-2026-55767 | 5.8 | 4.1 | — | Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle |
| CVE-2026-10099 | 5.1 | 2.6 | — | XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py |
| CVE-2026-25292 | 7.6 | 1.1 | — | Improper Validation of Syntactic Correctness of Input in Automotive Linux OS |
| CVE-2026-24087 | 7.2 | 0.9 | — | Improper Validation of Syntactic Correctness of Input in Kernel |
| CVE-2026-24089 | 7.2 | 0.9 | — | Improper Validation of Syntactic Correctness of Input in Kernel |
| CVE-2026-24091 | 7.2 | 0.9 | — | Improper Validation of Syntactic Correctness of Input in Display |
| CVE-2026-24092 | 7.2 | 0.9 | — | Improper Validation of Syntactic Correctness of Input in Display |
| Vendor | CVEs |
|---|---|
| qualcomm | 5 |
| dräger | 3 |
| netty | 2 |
| arista networks | 1 |
| fedify-dev | 1 |
| go standard library | 1 |
| guzzle | 1 |
| juniper networks | 1 |
| m-files | 1 |
| mastodon | 1 |
| microsoft | 1 |
| xx-net | 1 |