Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-252
Weakness type CWE-252 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 26 | 21 | 0 |
Monthly trend
▂▁▂▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▂▂▅█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 5 · 2026-09 10 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40092 | 7.5 | 53.6 | — | nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote… |
| CVE-2026-11972 | 8.2 | 52.1 | — | tarfile opened in streaming mode mishandles EOF |
| CVE-2025-58903 | 2.5 | 47.8 | — | — |
| CVE-2023-52687 | 5.5 | 47.0 | — | crypto: safexcel - Add error handling for dma_map_sg() calls |
| CVE-2026-26080 | 3.7 | 43.8 | — | — |
| CVE-2026-67409 | 8.2 | 40.0 | — | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes… |
| CVE-2026-14957 | 7.5 | 38.3 | — | FIPS mode assertion failure via malicious CERT payload |
| CVE-2026-19534 | 7.5 | 31.3 | — | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| CVE-2026-47245 | 4.3 | 28.2 | — | MyBB: Buddy list corruption |
| CVE-2026-86739 | 2.3 | 27.1 | — | Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence |
| CVE-2026-77641 | 8.2 | 26.7 | — | — |
| CVE-2026-79772 | 6.9 | 25.4 | — | Nokogiri before 1.19.1 Unchecked Return Value canonicalize |
| CVE-2026-86749 | 7.0 | 25.0 | — | snipe-it before 8.7.0 Data Loss via Failed Image Write |
| CVE-2026-18397 | 9.4 | 24.8 | — | SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability |
| CVE-2024-45775 | 5.2 | 19.8 | — | Grub2: commands/extcmd: missing check for failed allocation |
| CVE-2026-61857 | 6.3 | 16.8 | — | ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP |
| CVE-2026-62909 | 7.8 | 16.6 | — | .NET Elevation of Privilege Vulnerability |
| CVE-2024-42068 | 5.5 | 13.4 | — | bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro() |
| CVE-2024-42067 | 5.5 | 12.9 | — | bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro() |
| CVE-2026-85649 | 7.9 | 9.4 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 3 |
| grokability | 2 |
| imagemagick | 2 |
| ash-project | 1 |
| chewkeanho | 1 |
| dell | 1 |
| fortinet | 1 |
| 1 | |
| haproxy | 1 |
| microsoft | 1 |
| mybb | 1 |
| nimiq | 1 |
| python software foundation | 1 |
| rabbitmq | 1 |
| red hat | 1 |