Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-197
Weakness type CWE-197 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 47 | 41 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃██▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 5 · 2026-07 5 · 2026-08 15 · 2026-09 14 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-42475 | 9.3 | 99.9 | KEV | Fortinet FortiOS |
| CVE-2024-37337 | 4.3 | 75.8 | — | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |
| CVE-2024-21352 | 8.8 | 75.4 | — | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21391 | 8.8 | 75.4 | — | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-43519 | 8.8 | 73.3 | — | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2026-78512 | 8.8 | 55.7 | — | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-42944 | 8.7 | 54.2 | — | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options |
| CVE-2026-68880 | 8.0 | 54.0 | — | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-76151 | 4.6 | 50.3 | — | Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response head… |
| CVE-2024-21377 | 5.5 | 49.3 | — | Windows DNS Information Disclosure Vulnerability |
| CVE-2026-96280 | 7.5 | 46.8 | — | Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems |
| CVE-2026-55142 | 5.5 | 46.6 | — | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-19667 | 7.5 | 45.1 | — | Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` |
| CVE-2026-69512 | 8.8 | 44.5 | — | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-73523 | 8.7 | 44.0 | — | COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer Truncation |
| CVE-2026-6679 | 8.8 | 41.0 | — | DTLS 1.3 ACK serialization heap buffer overflow via integer truncation |
| CVE-2026-87529 | 9.6 | 40.9 | — | — |
| CVE-2026-44823 | 7.8 | 38.2 | — | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-63525 | 7.8 | 38.2 | — | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-68804 | 7.8 | 38.2 | — | Microsoft Excel Remote Code Execution Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 31 |
| red hat | 2 |
| capstone-engine | 1 |
| covesa | 1 |
| fortinet | 1 |
| 1 | |
| isc | 1 |
| nezhahq | 1 |
| nlnet labs | 1 |
| nnn | 1 |
| oisf | 1 |
| qt | 1 |
| ruby | 1 |
| samsung opensource | 1 |
| the document foundation | 1 |