Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1288
Weakness type CWE-1288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 15 | 1 |
Monthly trend
▂█▁▇▄▅▁
2026-04 1 · 2026-05 5 · 2026-06 0 · 2026-07 4 · 2026-08 2 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-31431 | 7.8 | 88.6 | KEV | crypto: algif_aead - Revert to operating out-of-place |
| CVE-2026-69793 | 7.5 | 55.9 | — | Windows TCP/IP Security Feature Bypass Vulnerability |
| CVE-2026-43001 | 8.0 | 46.2 | — | — |
| CVE-2026-31709 | 8.8 | 38.7 | — | smb: client: validate the whole DACL before rewriting it in cifsacl |
| CVE-2026-73219 | 5.3 | 38.1 | — | CVAT: Denial of service with regards to automatic annotation |
| CVE-2026-9689 | 4.2 | 35.0 | — | Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri all… |
| CVE-2026-18209 | 4.7 | 32.8 | — | Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http paramet… |
| CVE-2026-15943 | 5.5 | 24.8 | — | Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after… |
| CVE-2026-42982 | 7.8 | 24.4 | — | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-56744 | 8.7 | 20.8 | — | `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient o… |
| CVE-2026-18794 | 8.8 | 18.6 | — | OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and … |
| CVE-2026-14781 | 4.8 | 18.5 | — | Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to … |
| CVE-2026-31488 | 7.8 | 7.9 | — | drm/amd/display: Do not skip unrelated mode changes in DSC validation |
| CVE-2026-46117 | 7.8 | 7.5 | — | RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() |
| CVE-2026-18238 | 5.0 | 6.7 | — | OOBR in rpcap client in libpcap before 1.10.7 |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 4 |
| red hat | 4 |
| microsoft | 2 |
| bsv-blockchain | 1 |
| calcprogrammer1 | 1 |
| cvat-ai | 1 |
| openstack | 1 |
| the tcpdump group | 1 |