Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-193 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 45 | 36 | 0 |
▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▅▂
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 7 · 2026-06 16 · 2026-07 8 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50497 | 7.5 | 55.9 | — | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-42015 | 5.3 | 51.3 | — | Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling |
| CVE-2026-48689 | 9.8 | 49.5 | — | — |
| CVE-2026-12413 | 7.5 | 46.0 | — | IKEv2 Denial of Service via malformed fragmentation |
| CVE-2026-54410 | 7.8 | 43.1 | — | nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field |
| CVE-2024-47682 | 7.8 | 42.9 | — | scsi: sd: Fix off-by-one error in sd_read_block_characteristics() |
| CVE-2026-7831 | 7.6 | 42.3 | — | UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing |
| CVE-2026-49127 | 8.8 | 41.4 | — | Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be |
| CVE-2026-43964 | 7.5 | 40.3 | — | — |
| CVE-2026-66806 | 5.5 | 34.9 | — | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-53088 | 9.8 | 33.3 | — | net: bcmgenet: fix off-by-one in bcmgenet_put_txcb |
| CVE-2026-53309 | 9.8 | 33.3 | — | ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison |
| CVE-2026-44042 | 3.7 | 32.1 | — | UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check |
| CVE-2026-33997 | 8.1 | 32.0 | — | Moby: Off-by-one error in plugin privilege validation |
| CVE-2026-11771 | 7.0 | 30.7 | — | — |
| CVE-2026-52804 | 5.5 | 29.3 | — | Gogs: Privilege Escalation via Collaboration Access Mode Validation |
| CVE-2025-71161 | 5.5 | 27.2 | — | dm-verity: disable recursive forward error correction |
| CVE-2026-45232 | 2.1 | 26.8 | — | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy |
| CVE-2026-56787 | 6.9 | 26.6 | — | RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message |
| CVE-2026-71391 | 5.3 | 25.6 | — | Off-by-One Error in GNU Emacs for Android |