Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-325 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 14 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂█▅▁
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 4 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43547 | 6.5 | 48.5 | — | Windows Kerberos Information Disclosure Vulnerability |
| CVE-2026-45445 | 7.5 | 46.2 | — | AES-OCB IV Ignored on EVP_Cipher() Path |
| CVE-2026-42770 | 3.7 | 38.8 | — | FFC-DH Peer Validation Uses Attacker-Supplied q |
| CVE-2026-45446 | 4.8 | 30.6 | — | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| CVE-2026-42246 | 7.6 | 24.1 | — | net-imap vulnerable to STARTTLS stripping via invalid response timing |
| CVE-2026-4601 | 8.8 | 22.6 | — | — |
| CVE-2026-58638 | 5.5 | 14.0 | — | Windows Boot Loader Security Feature Bypass Vulnerability |
| CVE-2026-17666 | 9.1 | 8.9 | — | — |
| CVE-2026-48480 | 6.6 | 6.4 | — | netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Le… |
| CVE-2026-55144 | 7.1 | 6.1 | — | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability |
| CVE-2026-49440 | 7.4 | 4.6 | — | Deno: Miller-Rabin Primality Test Allows Zero Rounds |
| CVE-2026-59776 | 7.0 | 4.1 | — | — |
| CVE-2026-0420 | 4.6 | 3.5 | — | Missing TLS certificate validation in NETGEAR's ReadyCloud client app |
| CVE-2026-6458 | 5.1 | 2.9 | — | AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty |
| CVE-2026-9266 | 7.0 | 0.0 | — | — |