Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-459
Weakness type CWE-459 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 57 | 49 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂█▇▄
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 2 · 2026-08 19 · 2026-09 16 · 2026-10 9
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-52736 | 8.7 | 47.6 | — | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache |
| CVE-2026-42492 | 7.5 | 47.5 | — | vIRQ event channel binding may break Xenstore |
| CVE-2026-77761 | 6.3 | 47.5 | — | Cross-Document Parser State Contamination in misp-stix |
| CVE-2026-87776 | 7.5 | 47.4 | — | compression vulnerable to Denial of Service via memory leak on premature response close |
| CVE-2021-47178 | 5.5 | 46.1 | — | scsi: target: core: Avoid smp_processor_id() in preemptible code |
| CVE-2026-88932 | 5.3 | 43.1 | — | multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads |
| CVE-2026-19474 | 7.5 | 40.4 | — | @fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted u… |
| CVE-2026-19019 | 2.9 | 40.1 | — | poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence… |
| CVE-2026-5038 | 7.5 | 40.0 | — | multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
| CVE-2026-11576 | 7.5 | 37.9 | — | — |
| CVE-2026-85043 | 9.1 | 36.3 | — | — |
| CVE-2026-52733 | 6.5 | 35.8 | — | ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork … |
| CVE-2026-68809 | 5.5 | 35.7 | — | Powerpoint Information Disclosure Vulnerability |
| CVE-2025-6338 | 9.2 | 34.9 | — | Possible denial of service with multiple incoming connections to a Schannel based serve… |
| CVE-2026-95303 | 6.5 | 28.3 | — | — |
| CVE-2026-87549 | 6.5 | 28.3 | — | — |
| CVE-2026-106375 | 9.6 | 27.2 | — | — |
| CVE-2026-82236 | 2.3 | 26.7 | — | File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion |
| CVE-2026-77037 | 7.5 | 26.2 | — | multer vulnerable to Denial of Service via file descriptor leak on aborted uploads |
| CVE-2026-67442 | 2.0 | 23.4 | — | FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 17 | |
| linux | 7 |
| zcashfoundation | 4 |
| arista networks | 3 |
| multer | 3 |
| filebrowser | 2 |
| @fastify/multipart | 1 |
| ag-ui-protocol | 1 |
| apache | 1 |
| better-auth | 1 |
| capgo | 1 |
| compression | 1 |
| denx software engineering | 1 |
| eclipse foundation | 1 |
| elastic | 1 |