Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-401
Weakness type CWE-401 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 340 | 239 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▂▁▂▁▂▁▁▁▁▂▃▁▁▁▁▁▁███▃▆▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 4 · 2026-04 1 · 2026-05 58 · 2026-06 56 · 2026-07 56 · 2026-08 17 · 2026-09 41 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-26083 | 3.3 | 67.6 | KEV | Arm Mali Graphics Processing Unit (GPU) |
| CVE-2024-3653 | 5.3 | 78.6 | — | Undertow: learningpushhandler can lead to remote memory dos attacks |
| CVE-2024-1023 | 6.5 | 75.7 | — | Io.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structure… |
| CVE-2024-1394 | 7.5 | 73.9 | — | Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads |
| CVE-2026-3104 | 7.5 | 66.4 | — | Memory leak in code preparing DNSSEC proofs of non-existence |
| CVE-2026-35424 | 7.5 | 66.4 | — | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
| CVE-2026-44806 | 7.5 | 66.4 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2026-69588 | 7.5 | 66.4 | — | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-69809 | 7.5 | 66.4 | — | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-70065 | 7.5 | 66.4 | — | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69497 | 6.5 | 65.4 | — | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2024-27388 | 5.5 | 60.2 | — | SUNRPC: fix some memleaks in gssx_dec_option_array |
| CVE-2026-48059 | 8.7 | 57.7 | — | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M… |
| CVE-2026-48043 | 7.5 | 57.7 | — | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener … |
| CVE-2026-48006 | 8.7 | 56.7 | — | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| CVE-2024-27393 | 7.5 | 54.1 | — | xen-netfront: Add missing skb_mark_for_recycle |
| CVE-2026-69208 | 7.5 | 53.9 | — | Http4s: DigestAuth nonce map grows unbounded |
| CVE-2026-93436 | 8.7 | 53.5 | — | vLLM through 0.29.0 Memory Exhaustion via Rejected Requests |
| CVE-2026-12932 | 7.1 | 53.3 | — | — |
| CVE-2024-42152 | 4.7 | 52.8 | — | nvmet: fix a possible leak when destroy a ctrl during qp establishment |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 219 |
| imagemagick | 18 |
| red hat | 9 |
| microsoft | 8 |
| zephyrproject | 6 |
| eclipse foundation | 5 |
| netty | 5 |
| apache | 4 |
| spring | 3 |
| strongswan | 3 |
| cisco | 2 |
| gtermars | 2 |
| isc | 2 |
| libp2p | 2 |
| modelcontextprotocol | 2 |