Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-190 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 372 | 298 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▅
2025-09 2 · 2025-10 3 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 4 · 2026-05 26 · 2026-06 93 · 2026-07 105 · 2026-08 67
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-21823 | 7.8 | 92.2 | KEV | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2025-48595 | 8.4 | 75.6 | KEV | Android Framework |
| CVE-2023-21716 | 9.8 | 99.6 | — | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-47291 | 9.8 | 97.5 | — | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2023-36900 | 7.8 | 95.4 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-48933 | 7.5 | 88.9 | — | — |
| CVE-2023-35383 | 7.5 | 86.3 | — | Microsoft Message Queuing Information Disclosure Vulnerability |
| CVE-2023-36910 | 9.8 | 83.5 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-35385 | 9.8 | 83.2 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-49800 | 7.8 | 80.3 | — | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability |
| CVE-2023-35381 | 8.8 | 78.0 | — | Windows Fax Service Remote Code Execution Vulnerability |
| CVE-2026-8631 | 9.3 | 76.9 | — | HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrar… |
| CVE-2024-21372 | 8.8 | 76.8 | — | Windows OLE Remote Code Execution Vulnerability |
| CVE-2023-21803 | 9.8 | 76.3 | — | Windows iSCSI Discovery Service Remote Code Execution Vulnerability |
| CVE-2024-21420 | 8.8 | 75.8 | — | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21379 | 7.8 | 75.6 | — | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2023-36911 | 9.8 | 75.4 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2024-21350 | 8.8 | 71.9 | — | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2026-7838 | 8.7 | 70.4 | — | UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure rea… |
| CVE-2023-21797 | 8.8 | 65.4 | — | Microsoft ODBC Driver Remote Code Execution Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 87 |
| linux | 53 |
| 38 | |
| red hat | 20 |
| apple | 10 |
| libexpat project | 9 |
| adobe | 8 |
| mozilla | 8 |
| apache | 5 |
| radareorg | 5 |
| gnu | 4 |
| imagemagick | 4 |
| strukturag | 4 |
| freerdp | 3 |
| ggml-org | 3 |