Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-191 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 120 | 96 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▇▇█
2025-09 2 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 5 · 2026-05 7 · 2026-06 26 · 2026-07 26 · 2026-08 31
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42980 | 7.8 | 93.6 | — | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62696 | 7.8 | 87.0 | — | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2024-30070 | 7.5 | 82.0 | — | DHCP Server Service Denial of Service Vulnerability |
| CVE-2023-36909 | 6.5 | 79.8 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2024-0565 | 7.4 | 79.1 | — | Kernel: cifs filesystem decryption improper input validation remote code execution vuln… |
| CVE-2026-62741 | 7.8 | 78.6 | — | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-63362 | 8.2 | 72.7 | — | o6 Automation open62541 Integer Underflow |
| CVE-2023-21684 | 8.8 | 67.9 | — | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability |
| CVE-2023-35387 | 8.8 | 61.6 | — | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability |
| CVE-2026-55490 | 6.5 | 59.7 | — | OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service |
| CVE-2026-58058 | 6.9 | 56.3 | — | Nmap - Integer Underflow in IPv6 Extension Header Parsing |
| CVE-2026-33845 | 9.1 | 53.9 | — | Gnutls: gnutls: denial of service via dtls zero-length fragment |
| CVE-2026-49181 | 9.8 | 53.6 | — | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2024-26828 | 9.4 | 52.1 | — | cifs: fix underflow in parse_server_interfaces() |
| CVE-2023-21718 | 7.8 | 51.8 | — | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2026-53176 | 9.8 | 51.5 | — | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2022-49280 | 5.5 | 48.9 | — | NFSD: prevent underflow in nfssvc_decode_writeargs() |
| CVE-2026-42981 | 8.1 | 47.9 | — | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2022-48828 | 5.5 | 47.3 | — | NFSD: Fix ia_size underflow |
| CVE-2026-13308 | 8.1 | 44.5 | — | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vuln… |
| Vendor | CVEs |
|---|---|
| microsoft | 35 |
| linux | 27 |
| red hat | 10 |
| adobe | 4 |
| netatalk | 4 |
| absolute security | 2 |
| strukturag | 2 |
| apache | 1 |
| autel | 1 |
| capstone-engine | 1 |
| driftregion | 1 |
| erlang | 1 |
| ffmpeg | 1 |
| freebsd | 1 |
| freerdp | 1 |