Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-191
Weakness type CWE-191 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 186 | 160 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▅▅█▇▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 7 · 2026-05 9 · 2026-06 26 · 2026-07 27 · 2026-08 46 · 2026-09 41 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2014-0497 | 8.8 | 100.0 | KEV | Adobe Flash Player |
| CVE-2021-31956 | 7.8 | 97.6 | KEV | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2024-30070 | 7.5 | 82.8 | — | DHCP Server Service Denial of Service Vulnerability |
| CVE-2026-85436 | 8.7 | 81.0 | — | MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length |
| CVE-2023-36909 | 6.5 | 80.7 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2024-0565 | 7.4 | 80.0 | — | Kernel: cifs filesystem decryption improper input validation remote code execution vuln… |
| CVE-2026-63362 | 8.2 | 78.0 | — | o6 Automation open62541 Integer Underflow |
| CVE-2026-58058 | 6.9 | 72.5 | — | Nmap - Integer Underflow in IPv6 Extension Header Parsing |
| CVE-2023-21684 | 8.8 | 69.2 | — | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability |
| CVE-2026-66307 | 7.5 | 66.4 | — | Skype for Business and Lync Denial of Service Vulnerability |
| CVE-2026-49181 | 9.8 | 66.4 | — | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2023-35387 | 8.8 | 63.1 | — | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability |
| CVE-2026-58016 | 9.1 | 61.3 | — | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" |
| CVE-2026-69276 | 9.8 | 60.8 | — | Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
| CVE-2026-69824 | 9.8 | 60.8 | — | Microsoft Standard XPS Remote Code Execution Vulnerability |
| CVE-2026-91103 | 5.1 | 60.4 | — | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-84411 | 9.3 | 59.7 | — | MikroTik RouterOS Integer Underflow |
| CVE-2026-78453 | 6.5 | 59.0 | — | Microsoft Windows SCSI Class System File Information Disclosure Vulnerability |
| CVE-2026-71352 | 8.8 | 58.7 | — | Windows Remote Access Connection Manager Remote Code Execution Vulnerability |
| CVE-2026-71442 | 7.5 | 58.4 | — | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 49 |
| linux | 28 |
| adobe | 12 |
| red hat | 12 |
| watchguard | 6 |
| ibm | 5 |
| netatalk | 4 |
| apache | 3 |
| absolute security | 2 |
| freerdp | 2 |
| justicerage | 2 |
| mikrotik | 2 |
| mongodb | 2 |
| nvidia | 2 |
| rockwell automation | 2 |