Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-248 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 62 | 62 | 0 |
▂▁▂▃█▄
2026-03 3 · 2026-04 1 · 2026-05 5 · 2026-06 9 · 2026-07 32 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50328 | 7.5 | 65.2 | — | Windows Server Update Service (WSUS) Tampering Vulnerability |
| CVE-2026-2229 | 7.5 | 56.1 | — | undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s… |
| CVE-2026-34986 | 7.5 | 48.4 | — | Go JOSE affect by a panic in JWE decryption |
| CVE-2026-48068 | 7.5 | 46.9 | — | @grpc/grps-js: A malformed request can cause a server crash |
| CVE-2026-48069 | 7.5 | 46.9 | — | @grpc/grps-js: An incoming malformed compressed message can cause a client or server crash |
| CVE-2026-12644 | 5.5 | 41.2 | — | — |
| CVE-2026-31812 | 8.7 | 40.8 | — | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing |
| CVE-2026-1528 | 7.5 | 40.1 | — | undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and c… |
| CVE-2026-45685 | 7.5 | 38.4 | — | OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages |
| CVE-2026-47219 | 7.5 | 38.3 | — | find-my-way is Vulnerable to DDoS with HTTP2 |
| CVE-2026-73418 | 7.5 | 38.3 | — | NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization … |
| CVE-2026-59892 | 7.5 | 37.9 | — | OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled excepti… |
| CVE-2026-44001 | 8.6 | 37.5 | — | vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) |
| CVE-2026-14631 | 5.3 | 33.9 | — | webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header |
| CVE-2026-72813 | 6.9 | 32.8 | — | actix-files before 0.6.10 Denial of Service via empty Range header |
| CVE-2026-52739 | 5.9 | 32.7 | — | ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullif… |
| CVE-2026-59162 | 6.9 | 32.3 | — | Excelize: Negative shared-string index causes panic in GetCellValue and GetRows |
| CVE-2024-58368 | 8.7 | 32.0 | — | SurrealDB before 1.1.0 Denial of Service via HTTP Headers |
| CVE-2026-18675 | 5.3 | 31.7 | — | Kong Mesh: control plane denial of service via a malformed dataplane token with a non-s… |
| CVE-2026-52731 | 6.5 | 30.9 | — | ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate |
| Vendor | CVEs |
|---|---|
| surrealdb | 10 |
| open-telemetry | 3 |
| undici | 3 |
| zcashfoundation | 3 |
| elastic | 2 |
| gallagher | 2 |
| grpc | 2 |
| riebl | 2 |
| @auth | 1 |
| @fastify/middie | 1 |
| actix | 1 |
| browserslist | 1 |
| coredns | 1 |
| corewcf | 1 |
| delvedor | 1 |