Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-170 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 6 | 0 |
█▁▁▁▁▁▁▁▁▁▁▁▁▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅██▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-36906 | 7.5 | 78.9 | — | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2023-36907 | 7.5 | 75.8 | — | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2024-43474 | 7.5 | 67.2 | — | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-42010 | 9.8 | 61.6 | — | Gnutls: gnutls: authentication bypass via nul character in username |
| CVE-2026-5067 | 9.8 | 48.0 | — | Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocke… |
| CVE-2026-55738 | 8.7 | 33.2 | — | Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name … |
| CVE-2026-44452 | 5.9 | 16.7 | — | h2o is vulnerable to heap overrun |
| CVE-2026-12386 | 3.9 | 0.8 | — | Buffer Overflow in TUBITAK BILGEM's Pardus Pen |
| CVE-2026-45798 | 7.5 | — | — | Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-au… |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| h2o | 1 |
| red hat | 1 |
| rxi | 1 |
| tubitak bilgem software technologies research institute | 1 |
| wazuh | 1 |
| zephyrproject-rtos | 1 |