Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-129
Weakness type CWE-129 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 169 | 98 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▃▂▂▂▂▁▂▁▂▁▁▁▁▂▁▂▁▁▁▁▁▂▁▂▃█▄█▁
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 3 · 2026-04 2 · 2026-05 6 · 2026-06 10 · 2026-07 30 · 2026-08 14 · 2026-09 31 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-48503 | 8.8 | 87.8 | KEV | Apple Multiple Products |
| CVE-2021-38654 | 7.8 | 93.4 | — | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2026-3083 | 8.8 | 64.6 | — | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability |
| CVE-2023-2008 | 8.2 | 61.9 | — | Kernel: udmabuf: improper validation of array index leading to local privilege escalation |
| CVE-2026-32285 | 7.5 | 60.7 | — | Denial of service in github.com/buger/jsonparser |
| CVE-2026-91101 | 5.1 | 60.4 | — | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-22859 | 5.6 | 57.3 | — | FreeRDP has a heap-buffer-overflow in urb_select_configuration |
| CVE-2024-38587 | 7.8 | 54.6 | — | speakup: Fix sizeof() vs ARRAY_SIZE() bug |
| CVE-2026-55209 | 9.8 | 54.4 | — | resdata insufficiently validates untrusted GRDECL files |
| CVE-2026-45799 | 7.5 | 52.6 | — | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wir… |
| CVE-2026-15685 | 7.5 | 52.1 | — | Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability |
| CVE-2026-65652 | 8.7 | 51.9 | — | temporalio/tchannel-go malformed checksum type causes process termination |
| CVE-2026-65653 | 8.7 | 51.9 | — | temporalio/tchannel-go zero-chunk call fragment causes process termination |
| CVE-2026-32286 | 7.5 | 49.4 | — | Denial of service in github.com/jackc/pgproto3/v2 |
| CVE-2026-56111 | 8.3 | 49.2 | — | Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler |
| CVE-2026-84445 | 8.7 | 48.9 | — | gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` heade… |
| CVE-2025-21692 | 7.8 | 48.0 | — | net: sched: fix ets qdisc OOB Indexing |
| CVE-2026-52856 | 7.5 | 47.3 | — | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser… |
| CVE-2026-57159 | 8.4 | 46.6 | — | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
| CVE-2026-56770 | 8.7 | 45.9 | — | libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential … |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 87 |
| geovision | 11 |
| nvidia | 5 |
| vllm-project | 5 |
| ibm | 3 |
| temporal technologies | 3 |
| academysoftwarefoundation | 2 |
| apache | 2 |
| eugeny | 2 |
| imagemagick | 2 |
| red hat | 2 |
| square | 2 |
| timescale | 2 |
| tomwright | 2 |
| alsa project | 1 |