Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-130
Weakness type CWE-130 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 37 | 36 | 1 |
Monthly trend
▂▁▁▁▄▆▄▇██▆
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 5 · 2026-06 3 · 2026-07 6 · 2026-08 7 · 2026-09 7 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-14847 | 8.7 | 99.7 | KEV | Zlib compressed protocol header length confusion may allow memory read |
| CVE-2026-33846 | 7.5 | 65.1 | — | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment r… |
| CVE-2026-5367 | 8.6 | 57.7 | — | Ovn: ovn: information disclosure via crafted dhcpv6 packets |
| CVE-2026-90678 | 7.5 | 54.1 | — | — |
| CVE-2026-31635 | 7.5 | 48.4 | — | rxrpc: fix oversized RESPONSE authenticator length check |
| CVE-2026-58096 | 8.8 | 47.0 | — | ppp(8): missing length validation in LcpDecodeConfig() |
| CVE-2026-14587 | 5.5 | 43.6 | — | Unathenticated connection can hold Bolt channel open |
| CVE-2026-48685 | 6.5 | 43.2 | — | — |
| CVE-2026-77619 | 8.7 | 42.4 | — | Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory… |
| CVE-2026-9054 | 9.2 | 41.1 | — | Invalid IP packets cause a kernel panic |
| CVE-2026-73455 | 8.9 | 40.4 | — | Security Advisory 0173 |
| CVE-2026-41035 | 7.8 | 40.1 | — | — |
| CVE-2026-67292 | 9.3 | 39.1 | — | FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure |
| CVE-2026-26081 | 4.8 | 39.0 | — | — |
| CVE-2026-48487 | 5.3 | 38.2 | — | Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corrupt… |
| CVE-2026-81575 | 7.5 | 37.7 | — | Missing Sanity Checks for Buffer Lengths |
| CVE-2026-43125 | 9.8 | 34.7 | — | dlm: validate length in dlm_search_rsb_tree |
| CVE-2026-83745 | 8.7 | 34.6 | — | Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from… |
| CVE-2026-85494 | 8.7 | 34.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-94633 | 8.7 | 34.6 | — | Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 5 |
| silicon labs | 3 |
| freebsd | 2 |
| haproxy | 2 |
| linux | 2 |
| red hat | 2 |
| xen | 2 |
| 9front | 1 |
| abb | 1 |
| arista networks | 1 |
| envoyproxy | 1 |
| faye | 1 |
| freerdp | 1 |
| microsoft | 1 |
| mongodb | 1 |