Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-459 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 24 | 16 | 0 |
▂▁▁▁▁▁▁▂▁▁▁▂▁▂▂▁▂▁▁▂▁▁▁▁▁▁▁▃▂█
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 2 · 2026-08 11
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-47178 | 5.5 | 45.1 | — | scsi: target: core: Avoid smp_processor_id() in preemptible code |
| CVE-2026-42492 | 7.5 | 39.4 | — | vIRQ event channel binding may break Xenstore |
| CVE-2026-11576 | 7.5 | 38.2 | — | — |
| CVE-2026-52736 | 8.7 | 37.1 | — | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache |
| CVE-2025-6338 | 9.2 | 32.9 | — | Possible denial of service with multiple incoming connections to a Schannel based serve… |
| CVE-2026-52733 | 6.5 | 26.5 | — | ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork … |
| CVE-2026-19019 | 2.9 | 23.2 | — | poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence… |
| CVE-2026-67442 | 2.0 | 23.2 | — | FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup |
| CVE-2026-5038 | 7.5 | 20.4 | — | multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
| CVE-2026-19474 | 7.5 | 20.4 | — | @fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted u… |
| CVE-2026-68809 | 5.5 | 20.2 | — | Powerpoint Information Disclosure Vulnerability |
| CVE-2024-47674 | 5.5 | 16.1 | — | mm: avoid leaving partial pfn mappings around in error case |
| CVE-2024-57976 | 5.5 | 12.8 | — | btrfs: do proper folio cleanup when cow_file_range() failed |
| CVE-2024-57975 | 5.5 | 11.8 | — | btrfs: do proper folio cleanup when run_delalloc_nocow() failed |
| CVE-2025-21924 | 5.5 | 10.6 | — | net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns a… |
| CVE-2026-67334 | 5.1 | 10.1 | — | better-auth Stale Sessions Persist After User Deletion |
| CVE-2025-37908 | 7.8 | 8.2 | — | mm, slab: clean up slab->obj_exts always |
| CVE-2026-53867 | 5.3 | 8.2 | — | Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement |
| CVE-2025-38177 | 5.5 | 5.9 | — | sch_hfsc: make hfsc_qlen_notify() idempotent |
| CVE-2026-9693 | 3.5 | 5.3 | — | Mattermost thread memberships persist after team removal, exposing private channel thre… |
| Vendor | CVEs |
|---|---|
| linux | 7 |
| zcashfoundation | 2 |
| @fastify/multipart | 1 |
| better-auth | 1 |
| capgo | 1 |
| eclipse foundation | 1 |
| frangoteam | 1 |
| imagination technologies | 1 |
| mattermost | 1 |
| microsoft | 1 |
| multer | 1 |
| poco-ai | 1 |
| qt | 1 |
| red hat | 1 |
| sharp | 1 |