Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-415
Weakness type CWE-415 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 229 | 129 | 6 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▂▂▂▂▂▂▂▁▂▁▁▂▂▂▁▂▂▁▁▂▁▁▂▄▄▆▄█▁
2025-11 1 · 2025-12 0 · 2026-01 4 · 2026-02 0 · 2026-03 0 · 2026-04 7 · 2026-05 16 · 2026-06 17 · 2026-07 30 · 2026-08 16 · 2026-09 39 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-4990 | 8.8 | 98.4 | KEV | Adobe Acrobat and Reader |
| CVE-2014-0502 | 8.8 | 97.8 | KEV | Adobe Flash Player |
| CVE-2021-22600 | 6.6 | 93.6 | KEV | Double Free in net/packet/af_packet.c leading to priviledge escalation |
| CVE-2025-62215 | 7.0 | 93.1 | KEV | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-33824 | 9.8 | 75.2 | KEV | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability |
| CVE-2020-9859 | 7.8 | 56.1 | KEV | Apple Multiple Products |
| CVE-2024-30097 | 8.8 | 76.8 | — | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnera… |
| CVE-2026-18798 | 7.5 | 74.0 | — | QUIC Server May Trigger Double Free When Processing INITIAL Packet |
| CVE-2025-32988 | 8.2 | 71.0 | — | Gnutls: vulnerability in gnutls othername san export |
| CVE-2026-8925 | 9.8 | 63.9 | — | SASL double-free |
| CVE-2023-35371 | 7.8 | 61.1 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-77493 | 9.8 | 60.8 | — | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-66373 | 7.5 | 57.5 | — | — |
| CVE-2026-33630 | 7.5 | 56.5 | — | c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely tri… |
| CVE-2026-77504 | 8.8 | 55.7 | — | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-80080 | 8.8 | 55.7 | — | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-33811 | 7.5 | 55.5 | — | Crash when handling long CNAME response in net |
| CVE-2026-69322 | 8.0 | 54.0 | — | Microsoft Windows Search Component Elevation of Privilege Vulnerability |
| CVE-2026-14164 | 7.5 | 52.8 | — | Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered… |
| CVE-2026-55007 | 8.1 | 52.4 | — | Microsoft Exchange Server Remote Code Execution Vulnerability |