Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-193
Weakness type CWE-193 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 68 | 57 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▅▅▇▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 7 · 2026-06 16 · 2026-07 9 · 2026-08 9 · 2026-09 14 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-3156 | 7.8 | 100.0 | KEV | Sudo Sudo |
| CVE-2026-86297 | 8.2 | 65.1 | — | D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one |
| CVE-2026-50497 | 7.5 | 59.0 | — | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-42015 | 5.3 | 58.9 | — | Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling |
| CVE-2026-48689 | 9.8 | 58.6 | — | — |
| CVE-2026-43964 | 7.5 | 57.8 | — | — |
| CVE-2026-54410 | 7.8 | 57.1 | — | nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field |
| CVE-2026-53088 | 9.8 | 53.5 | — | net: bcmgenet: fix off-by-one in bcmgenet_put_txcb |
| CVE-2026-7831 | 7.6 | 52.9 | — | UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing |
| CVE-2026-58014 | 8.6 | 52.3 | — | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" |
| CVE-2026-65927 | 7.5 | 50.9 | — | Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control |
| CVE-2026-11771 | 7.0 | 50.9 | — | — |
| CVE-2026-49127 | 8.8 | 50.6 | — | Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be |
| CVE-2026-12413 | 7.5 | 46.8 | — | IKEv2 Denial of Service via malformed fragmentation |
| CVE-2026-56787 | 6.9 | 44.9 | — | RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message |
| CVE-2026-46369 | 7.5 | 44.0 | — | Nimiq: Validity store off by one error |
| CVE-2026-83600 | 6.5 | 44.0 | — | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation reque… |
| CVE-2026-71391 | 5.3 | 43.6 | — | Off-by-One Error in GNU Emacs for Android |
| CVE-2024-47682 | 7.8 | 43.2 | — | scsi: sd: Fix off-by-one error in sd_read_block_characteristics() |
| CVE-2026-64047 | 9.8 | 41.7 | — | net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 18 |
| microsoft | 4 |
| red hat | 3 |
| imagemagick | 2 |
| openvpn | 2 |
| rti | 2 |
| trusted domain project | 2 |
| uvnc | 2 |
| alsa project | 1 |
| apache | 1 |
| canboat | 1 |
| d-link | 1 |
| debevv | 1 |
| freerdp | 1 |
| gnome | 1 |