Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-248
Weakness type CWE-248 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 122 | 122 | 0 |
Monthly trend
▂▁▂▃▇▅█▃
2026-03 4 · 2026-04 1 · 2026-05 5 · 2026-06 9 · 2026-07 32 · 2026-08 22 · 2026-09 39 · 2026-10 10
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50328 | 7.5 | 67.9 | — | Windows Server Update Service (WSUS) Tampering Vulnerability |
| CVE-2026-69839 | 6.5 | 65.4 | — | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-92905 | 5.3 | 60.7 | — | Denial of Service Vulnerability |
| CVE-2026-32641 | 7.5 | 59.0 | — | Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middle… |
| CVE-2026-31812 | 8.7 | 58.0 | — | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing |
| CVE-2026-48068 | 7.5 | 57.7 | — | @grpc/grps-js: A malformed request can cause a server crash |
| CVE-2026-48069 | 7.5 | 57.7 | — | @grpc/grps-js: An incoming malformed compressed message can cause a client or server crash |
| CVE-2026-73418 | 7.5 | 57.6 | — | NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization … |
| CVE-2026-2229 | 7.5 | 57.5 | — | undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s… |
| CVE-2026-59892 | 7.5 | 54.5 | — | OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled excepti… |
| CVE-2026-33939 | 7.5 | 53.6 | — | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation |
| CVE-2026-64612 | 7.5 | 51.7 | — | Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malfo… |
| CVE-2026-44001 | 8.6 | 50.1 | — | vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) |
| CVE-2026-73088 | 7.5 | 49.7 | — | Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json cu… |
| CVE-2026-59162 | 6.9 | 49.6 | — | Excelize: Negative shared-string index causes panic in GetCellValue and GetRows |
| CVE-2024-58368 | 8.7 | 49.5 | — | SurrealDB before 1.1.0 Denial of Service via HTTP Headers |
| CVE-2026-34986 | 7.5 | 49.4 | — | Go JOSE affect by a panic in JWE decryption |
| CVE-2026-84445 | 8.7 | 48.9 | — | gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` heade… |
| CVE-2026-45685 | 7.5 | 48.5 | — | OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages |
| CVE-2026-94622 | 8.7 | 48.2 | — | vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 12 |
| surrealdb | 10 |
| undici | 7 |
| elastic | 3 |
| grpc | 3 |
| open-telemetry | 3 |
| patriksimek | 3 |
| zcashfoundation | 3 |
| gallagher | 2 |
| microsoft | 2 |
| mongodb | 2 |
| nimiq | 2 |
| pmmp | 2 |
| rclone | 2 |
| riebl | 2 |