Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-404
Weakness type CWE-404 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 142 | 135 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▃▄▄█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 18 · 2026-06 15 · 2026-07 24 · 2026-08 21 · 2026-09 56 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-8120 | 7.0 | 99.5 | KEV | Microsoft Win32k |
| CVE-2018-8639 | 8.4 | 97.6 | KEV | Microsoft Windows |
| CVE-2018-8611 | 7.8 | 90.6 | KEV | Microsoft Windows |
| CVE-2018-8405 | 7.8 | 88.6 | KEV | Microsoft DirectX Graphics Kernel (DXGKRNL) |
| CVE-2018-8406 | 7.8 | 88.6 | KEV | Microsoft DirectX Graphics Kernel (DXGKRNL) |
| CVE-2025-9784 | 7.5 | 82.9 | — | Undertow: undertow madeyoureset http/2 ddos vulnerability |
| CVE-2026-82669 | 5.5 | 53.0 | — | klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service |
| CVE-2026-17500 | 6.9 | 52.4 | — | ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference |
| CVE-2026-17501 | 6.9 | 52.4 | — | ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform … |
| CVE-2026-78148 | 6.9 | 52.4 | — | ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference |
| CVE-2026-9540 | 5.5 | 52.4 | — | vllm-project vllm OpenAI-compatible Serving Path denial of service |
| CVE-2026-90784 | 5.5 | 52.4 | — | Dvidelabs flatcc semantics.c fb_clear_parser memory leak |
| CVE-2026-91855 | 5.5 | 52.4 | — | Open5GS PFCP Message handler.c denial of service |
| CVE-2026-41869 | 9.1 | 52.3 | — | Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nut… |
| CVE-2026-92220 | 6.9 | 51.6 | — | vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_rele… |
| CVE-2026-82803 | 5.5 | 51.6 | — | armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null poi… |
| CVE-2026-84856 | 5.5 | 51.6 | — | rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service |
| CVE-2026-86319 | 5.5 | 51.6 | — | java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource cons… |
| CVE-2026-86511 | 5.5 | 51.6 | — | java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource c… |
| CVE-2026-90582 | 5.5 | 51.6 | — | evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| gnu | 12 |
| oracle | 6 |
| vllm-project | 6 |
| microsoft | 5 |
| ag-ui-protocol | 4 |
| ggml-org | 4 |
| nousresearch | 4 |
| simular-ai | 3 |
| apache | 2 |
| barebones | 2 |
| calix | 2 |
| connorskees | 2 |
| java-json-tools | 2 |
| linux | 2 |
| omec-project | 2 |