Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-406
Weakness type CWE-406 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 6 | 5 | 1 |
Monthly trend
▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 2 · 2026-08 1 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-0028 | 8.6 | 84.5 | KEV | PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering |
| CVE-2026-68080 | 6.5 | 49.5 | — | Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service |
| CVE-2026-50045 | 5.3 | 38.0 | — | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2026-54609 | 8.6 | 37.7 | — | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST… |
| CVE-2026-86202 | 5.3 | 26.9 | — | PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket |
| CVE-2026-16515 | 4.7 | 8.9 | — | ICMPv6 error messages sent for multicast-destined packets and non-unique source address… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 1 |
| nlnet labs | 1 |
| palo alto networks | 1 |
| pmmp | 1 |
| quiet-terminal-interactive | 1 |
| zephyrproject | 1 |