Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-404 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 68 | 66 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆▅█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 18 · 2026-06 15 · 2026-07 24 · 2026-08 9
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-8120 | 7.0 | 99.4 | KEV | Microsoft Win32k |
| CVE-2025-15687 | 2.1 | 46.6 | — | Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service |
| CVE-2025-15686 | 2.1 | 41.4 | — | Open5GS HSS Service fd_msg_sess_get denial of service |
| CVE-2026-38641 | 7.5 | 37.3 | — | — |
| CVE-2026-10069 | 8.7 | 36.7 | — | Shibby Tomato miniupnpd resource consumption |
| CVE-2026-10650 | 5.5 | 35.9 | — | warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption |
| CVE-2026-9540 | 5.5 | 35.8 | — | vllm-project vllm OpenAI-compatible Serving Path denial of service |
| CVE-2026-17500 | 6.9 | 35.1 | — | ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference |
| CVE-2026-17501 | 6.9 | 35.1 | — | ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform … |
| CVE-2026-13491 | 2.9 | 34.5 | — | 78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service |
| CVE-2026-10116 | 2.1 | 32.4 | — | Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service |
| CVE-2026-10224 | 5.5 | 30.5 | — | NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource c… |
| CVE-2026-19362 | 5.5 | 30.5 | — | lmammino oidc-authorizer Authorization Header Parsing parse_token_from_header.rs parse_… |
| CVE-2026-10190 | 5.7 | 30.0 | — | Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service |
| CVE-2026-75012 | 5.7 | 29.2 | — | TOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null pointer derefer… |
| CVE-2026-75013 | 5.7 | 29.2 | — | TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference |
| CVE-2026-59725 | 7.5 | 28.6 | — | Socket.IO: Engine.IO Polling Transport Connection Exhaustion |
| CVE-2026-60624 | 6.5 | 28.3 | — | — |
| CVE-2026-19745 | 2.1 | 27.7 | — | Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service |
| CVE-2026-19746 | 2.1 | 27.7 | — | Calix GigaSpire traceroute.cmd denial of service |
| Vendor | CVEs |
|---|---|
| oracle | 5 |
| ggml-org | 3 |
| gnu | 3 |
| calix | 2 |
| connorskees | 2 |
| linux | 2 |
| nousresearch | 2 |
| omec-project | 2 |
| totolink | 2 |
| 78 | 1 |
| aio-libs | 1 |
| almico | 1 |
| boxlite-ai | 1 |
| bytedance | 1 |
| cyberark software, a palo alto networks company | 1 |