Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-134
Weakness type CWE-134 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 39 | 36 | 3 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▇█▆▆▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 1 · 2026-06 8 · 2026-07 9 · 2026-08 7 · 2026-09 7 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-23113 | 9.8 | 99.2 | KEV | Fortinet Multiple Products |
| CVE-2019-1579 | 8.1 | 98.8 | KEV | Palo Alto Networks PAN-OS |
| CVE-2020-3118 | 8.8 | 95.9 | KEV | Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability |
| CVE-2026-63073 | 9.8 | 66.0 | — | Untrusted Sender DN Used as Format String in CMP Response Validation |
| CVE-2026-33210 | 8.3 | 61.8 | — | Ruby JSON has a format string injection vulnerability |
| CVE-2026-69395 | 6.5 | 61.4 | — | Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability |
| CVE-2026-6250 | 7.0 | 59.6 | — | Authenticated Format String Injection on TP-Link Tapo C110 |
| CVE-2026-17136 | 9.8 | 54.9 | — | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-14157 | 9.4 | 53.8 | — | — |
| CVE-2026-12174 | 7.4 | 45.9 | — | D-Link DCS-935L HTTP rhea snprintf format string |
| CVE-2024-58366 | 9.0 | 45.5 | — | SurrealDB before 1.1.1 Format String via Scripting Functions |
| CVE-2026-76722 | 9.8 | 43.4 | — | Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-S… |
| CVE-2026-50211 | 8.8 | 42.3 | — | Exposed Factory Testing App Boundaries |
| CVE-2026-67244 | 8.6 | 40.6 | — | A format string vulnerability was found in the Notification OAuth settings of ADM |
| CVE-2026-12004 | 8.7 | 40.3 | — | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security… |
| CVE-2026-68553 | 7.1 | 39.2 | — | Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command |
| CVE-2026-18186 | 7.1 | 38.0 | — | A stored format string vulnerability was found in the FTP Backup on the ADM |
| CVE-2026-18187 | 7.1 | 38.0 | — | A format string vulnerability was found in the Internal Backup on the ADM |
| CVE-2026-18188 | 7.1 | 38.0 | — | A format string vulnerability was found in the Rsync Backup on the ADM |
| CVE-2026-57877 | 8.6 | 35.4 | — | GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr) |