Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-401 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 269 | 175 | 0 |
▂▁▃▁▂▁▁▁▁▂▂▂▁▂▁▁▂▁▂▃▁▁▁▁▁▁██▇▂
2025-09 6 · 2025-10 12 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 2 · 2026-04 1 · 2026-05 56 · 2026-06 56 · 2026-07 49 · 2026-08 10
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-3653 | 5.3 | 77.6 | — | Undertow: learningpushhandler can lead to remote memory dos attacks |
| CVE-2024-1023 | 6.5 | 74.6 | — | Io.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structure… |
| CVE-2024-1394 | 7.5 | 72.8 | — | Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads |
| CVE-2026-35424 | 7.5 | 65.4 | — | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
| CVE-2024-27388 | 5.5 | 58.7 | — | SUNRPC: fix some memleaks in gssx_dec_option_array |
| CVE-2026-44806 | 7.5 | 54.3 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2024-27393 | 7.5 | 52.8 | — | xen-netfront: Add missing skb_mark_for_recycle |
| CVE-2026-48006 | 8.7 | 51.8 | — | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| CVE-2024-42152 | 4.7 | 51.5 | — | nvmet: fix a possible leak when destroy a ctrl during qp establishment |
| CVE-2023-52610 | 5.5 | 47.9 | — | net/sched: act_ct: fix skb leak and crash on ooo frags |
| CVE-2026-58175 | 8.2 | 47.7 | — | Apache Traffic Server: HostDB SRV handling leaks memory |
| CVE-2026-48059 | 8.7 | 47.5 | — | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M… |
| CVE-2026-1605 | 7.5 | 47.3 | — | — |
| CVE-2026-48043 | 7.5 | 46.9 | — | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener … |
| CVE-2024-36911 | 5.5 | 46.6 | — | hv_netvsc: Don't free decrypted memory |
| CVE-2024-38539 | 5.5 | 46.5 | — | RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw |
| CVE-2024-35882 | 5.5 | 45.9 | — | SUNRPC: Fix a slow server-side memory leak with RPC-over-TCP |
| CVE-2024-27066 | 5.5 | 45.7 | — | virtio: packed: fix unmap leak for indirect desc table |
| CVE-2025-46420 | 6.5 | 44.2 | — | Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c |
| CVE-2024-53178 | 4.7 | 43.1 | — | smb: Don't leak cfid when reconnect races with open_cached_dir |
| Vendor | CVEs |
|---|---|
| linux | 200 |
| imagemagick | 18 |
| netty | 5 |
| red hat | 5 |
| eclipse foundation | 3 |
| gtermars | 2 |
| microsoft | 2 |
| offis dicom | 2 |
| openvpn | 2 |
| zephyrproject | 2 |
| almico | 1 |
| amazon | 1 |
| apache | 1 |
| canonical | 1 |
| generalsandman | 1 |