Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-131 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 28 | 27 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▄▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 13 · 2026-07 6 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42055 | 9.2 | 89.7 | — | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability |
| CVE-2026-44420 | 8.8 | 88.7 | — | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CL… |
| CVE-2026-2049 | 7.8 | 46.8 | — | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-43501 | 9.8 | 45.8 | — | ipv6: rpl: reserve mac_len headroom when recompressed SRH grows |
| CVE-2026-2050 | 7.8 | 43.7 | — | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-45812 | 6.5 | 35.2 | — | Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler |
| CVE-2026-49841 | 9.8 | 32.8 | — | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read |
| CVE-2026-42915 | 5.5 | 31.6 | — | Microsoft Windows VMSwitch Denial of Service Vulnerability |
| CVE-2026-52955 | 9.8 | 31.3 | — | libceph: Fix potential out-of-bounds access in crush_decode() |
| CVE-2026-70457 | 8.3 | 29.3 | — | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() |
| CVE-2026-75093 | 2.1 | 27.6 | — | sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size |
| CVE-2026-55827 | 8.8 | 27.0 | — | FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode |
| CVE-2026-11604 | 5.6 | 26.8 | — | — |
| CVE-2026-10701 | 7.5 | 22.8 | — | Incorrect boundary conditions in the Graphics: Text component |
| CVE-2026-54696 | 3.7 | 22.8 | — | Ruby JSON: JSON generator heap buffer overflow when streaming to an IO |
| CVE-2024-42259 | 5.5 | 18.5 | — | drm/i915/gem: Fix Virtual Memory mapping boundaries calculation |
| CVE-2026-0280 | 1.7 | 8.8 | — | PAN-OS: IPv6 Firewall Policy Bypass |
| CVE-2026-42170 | 7.8 | 8.7 | — | Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (dds… |
| CVE-2026-8357 | 5.4 | 5.4 | — | Heap buffer overflow in Calc formula compilation |
| CVE-2026-53143 | 7.8 | 4.1 | — | drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 |
| Vendor | CVEs |
|---|---|
| linux | 5 |
| ffmpeg | 2 |
| freerdp | 2 |
| gimp | 2 |
| red hat | 2 |
| apache | 1 |
| f5 | 1 |
| imagemagick | 1 |
| microsoft | 1 |
| mozilla | 1 |
| openvpn | 1 |
| palo alto networks | 1 |
| rsyncproject | 1 |
| ruby | 1 |
| rust-openssl | 1 |