Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-131
Weakness type CWE-131 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 52 | 49 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▂▃█▄▅█▂
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 13 · 2026-07 6 · 2026-08 8 · 2026-09 14 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-17087 | 7.8 | 92.5 | KEV | Windows Kernel Local Elevation of Privilege Vulnerability |
| CVE-2026-42055 | 9.2 | 93.6 | — | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability |
| CVE-2026-42945 | 9.2 | 88.4 | — | NGINX ngx_http_rewrite_module vulnerability |
| CVE-2026-43501 | 9.8 | 61.2 | — | ipv6: rpl: reserve mac_len headroom when recompressed SRH grows |
| CVE-2026-44420 | 8.8 | 56.9 | — | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CL… |
| CVE-2026-69598 | 8.8 | 55.7 | — | Windows iSCSI Remote Code Execution Vulnerability |
| CVE-2026-42944 | 8.7 | 54.2 | — | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options |
| CVE-2026-39892 | 6.9 | 53.6 | — | cryptography has a buffer overflow if non-contiguous buffers were passed to APIs |
| CVE-2026-78002 | 7.5 | 51.8 | — | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() … |
| CVE-2026-45812 | 6.5 | 51.3 | — | Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler |
| CVE-2026-34986 | 7.5 | 49.4 | — | Go JOSE affect by a panic in JWE decryption |
| CVE-2026-2049 | 7.8 | 47.6 | — | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-2050 | 7.8 | 47.6 | — | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
| CVE-2026-49841 | 9.8 | 47.1 | — | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read |
| CVE-2026-75093 | 2.1 | 46.5 | — | sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size |
| CVE-2026-16924 | 7.5 | 44.0 | — | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-55827 | 8.8 | 43.0 | — | FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode |
| CVE-2026-52955 | 9.8 | 41.3 | — | libceph: Fix potential out-of-bounds access in crush_decode() |
| CVE-2026-44254 | 5.3 | 40.5 | — | Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path |
| CVE-2026-42915 | 5.5 | 31.8 | — | Microsoft Windows VMSwitch Denial of Service Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 6 |
| linux | 5 |
| freerdp | 3 |
| microsoft | 3 |
| f5 | 2 |
| ffmpeg | 2 |
| gimp | 2 |
| openvpn | 2 |
| academysoftwarefoundation | 1 |
| altera | 1 |
| apache | 1 |
| arduino-libraries | 1 |
| eclipse foundation | 1 |
| eprosima | 1 |
| gnu | 1 |