Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1333 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 69 | 63 | 0 |
▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▆█▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 17 · 2026-07 25 · 2026-08 15
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-10270 | 6.5 | 67.3 | — | Org.keycloak:keycloak-services: keycloak denial of service |
| CVE-2023-6159 | 6.5 | 59.9 | — | Inefficient Regular Expression Complexity in GitLab |
| CVE-2024-21538 | 7.7 | 55.9 | — | — |
| CVE-2026-45305 | 8.7 | 53.9 | — | Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| CVE-2026-4926 | 7.5 | 53.5 | — | path-to-regexp vulnerable to Denial of Service via sequential optional groups |
| CVE-2026-45133 | 8.2 | 51.8 | — | Symfony: [Yaml] Harden the parser when handling untrusted input |
| CVE-2026-28356 | 7.5 | 51.0 | — | ReDoS in multipart 1.3.0 - `parse_options_header()` |
| CVE-2026-69207 | 5.3 | 48.5 | — | Hono: ReDoS in CORS middleware via Access-Control-Request-Headers |
| CVE-2026-44496 | 7.5 | 47.1 | — | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| CVE-2023-6489 | 4.3 | 46.1 | — | Inefficient Regular Expression Complexity in GitLab |
| CVE-2026-45756 | 8.2 | 46.0 | — | Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search()… |
| CVE-2026-47138 | 8.7 | 45.4 | — | Parse Server: Pre-authentication denial of service via client version header regex back… |
| CVE-2026-67422 | 7.5 | 45.2 | — | pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magic… |
| CVE-2026-52778 | 9.8 | 44.2 | — | YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial … |
| CVE-2026-49477 | 7.5 | 42.1 | — | Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser |
| CVE-2026-33079 | 8.7 | 41.8 | — | Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles |
| CVE-2025-6069 | 4.3 | 41.8 | — | HTMLParser quadratic complexity when processing malformed inputs |
| CVE-2025-69873 | 2.9 | 40.3 | — | — |
| CVE-2026-45367 | 7.5 | 40.1 | — | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint |
| CVE-2024-21539 | 7.7 | 39.6 | — | — |
| Vendor | CVEs |
|---|---|
| lepture | 5 |
| hapifhir | 3 |
| open-webui | 3 |
| symfony | 3 |
| andialbrecht | 2 |
| facelessuser | 2 |
| getgrav | 2 |
| gitlab | 2 |
| red hat | 2 |
| sveltejs | 2 |
| vllm-project | 2 |
| ajv.js | 1 |
| angular | 1 |
| apache | 1 |
| axios | 1 |