Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-130 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 17 | 0 |
▂▇▅█▃
2026-04 1 · 2026-05 5 · 2026-06 3 · 2026-07 6 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33846 | 7.5 | 67.3 | — | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment r… |
| CVE-2026-31635 | 7.5 | 54.3 | — | rxrpc: fix oversized RESPONSE authenticator length check |
| CVE-2026-43125 | 9.8 | 35.7 | — | dlm: validate length in dlm_search_rsb_tree |
| CVE-2026-14587 | 5.5 | 31.4 | — | Unathenticated connection can hold Bolt channel open |
| CVE-2026-26081 | 4.8 | 29.5 | — | — |
| CVE-2026-6432 | 5.3 | 23.6 | — | Improper bounds validation in EmberZNet SDK |
| CVE-2026-48685 | 6.5 | 22.2 | — | — |
| CVE-2026-9054 | 9.2 | 21.7 | — | Invalid IP packets cause a kernel panic |
| CVE-2026-45681 | 5.9 | 21.3 | — | OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB… |
| CVE-2026-67292 | 9.3 | 18.4 | — | FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure |
| CVE-2026-48487 | 5.3 | 16.4 | — | Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corrupt… |
| CVE-2026-54466 | 9.2 | 13.0 | — | websocket-driver: Message corruption via abuse of protocol length headers |
| CVE-2026-62423 | 5.5 | 10.9 | — | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-62424 | 5.5 | 10.9 | — | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-45615 | 8.2 | 9.8 | — | mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed … |
| CVE-2026-60060 | 5.1 | 8.0 | — | — |
| CVE-2026-47692 | 4.3 | 3.7 | — | Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-… |
| Vendor | CVEs |
|---|---|
| linux | 2 |
| xen | 2 |
| 9front | 1 |
| envoyproxy | 1 |
| faye | 1 |
| freerdp | 1 |
| haproxy | 1 |
| mouse07410 | 1 |
| neo4j | 1 |
| open-telemetry | 1 |
| python-zeroconf | 1 |
| red hat | 1 |
| silicon labs | 1 |
| teraterm project | 1 |