Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-416 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 2113 | 1254 | 12 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▂▂▁▂▁▂▁▂▂▁▁▁▂▁▁▁▁▁▁▂▃█▆▃
2025-09 60 · 2025-10 33 · 2025-11 2 · 2025-12 0 · 2026-01 28 · 2026-02 7 · 2026-03 3 · 2026-04 58 · 2026-05 170 · 2026-06 499 · 2026-07 352 · 2026-08 137
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-3992 | 9.8 | 99.6 | KEV | VMware ESXi |
| CVE-2018-15982 | 7.8 | 99.6 | KEV | Adobe Flash Player |
| CVE-2021-26411 | 8.8 | 99.6 | KEV | Internet Explorer Memory Corruption Vulnerability |
| CVE-2021-22893 | 10.0 | 98.7 | KEV | Ivanti Pulse Connect Secure |
| CVE-2024-1086 | 7.8 | 98.0 | KEV | Use-after-free in Linux kernel's netfilter: nf_tables component |
| CVE-2024-9680 | 9.8 | 97.6 | KEV | Mozilla Firefox |
| CVE-2025-29824 | 7.8 | 96.2 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-2586 | 7.8 | 95.4 | KEV | Linux Kernel |
| CVE-2021-34486 | 7.8 | 94.9 | KEV | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2026-5281 | 8.8 | 91.5 | KEV | Google Dawn |
| CVE-2024-36971 | 7.8 | 84.7 | KEV | net: fix __dst_negative_advice() race |
| CVE-2026-68820 | 7.0 | 26.2 | KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2024-30080 | 9.8 | 98.6 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2025-21760 | 8.1 | 98.4 | — | ndisc: extend RCU protection in ndisc_send_skb() |
| CVE-2026-45657 | 9.8 | 96.5 | — | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2024-43491 | 9.8 | 95.9 | — | Microsoft Windows Update Remote Code Execution Vulnerability |
| CVE-2025-26670 | 8.1 | 95.4 | — | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability |
| CVE-2025-27480 | 8.1 | 95.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2024-30089 | 7.8 | 94.3 | — | Microsoft Streaming Service Elevation of Privilege Vulnerability |
| CVE-2025-21759 | 7.8 | 93.9 | — | ipv6: mcast: extend RCU protection in igmp6_send() |
| Vendor | CVEs |
|---|---|
| linux | 944 |
| 462 | |
| microsoft | 440 |
| apple | 42 |
| mozilla | 21 |
| zephyrproject | 16 |
| foxit software | 15 |
| adobe | 13 |
| red hat | 13 |
| imagemagick | 7 |
| sparklemotion | 7 |
| freebsd | 6 |
| mongodb | 6 |
| apache | 5 |
| imagination technologies | 5 |