Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-476
Weakness type CWE-476 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 848 | 558 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▁▂▂▁▂▂▂▁▂▂▂▂▁▂▂▁▁▁▁▂▁▅█▇▆▆▁
2025-11 0 · 2025-12 1 · 2026-01 6 · 2026-02 7 · 2026-03 10 · 2026-04 8 · 2026-05 85 · 2026-06 135 · 2026-07 119 · 2026-08 87 · 2026-09 95 · 2026-10 6
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21525 | 6.2 | 91.7 | KEV | Windows Remote Access Connection Manager Denial of Service Vulnerability |
| CVE-2025-22037 | 5.5 | 99.3 | — | ksmbd: fix null pointer dereference in alloc_preauth_hash() |
| CVE-2023-3866 | 5.5 | 95.8 | — | ksmbd: validate session id and tree id in the compound request |
| CVE-2020-1069 | 8.8 | 90.2 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2024-21404 | 7.5 | 85.5 | — | .NET Denial of Service Vulnerability |
| CVE-2024-38233 | 7.5 | 83.8 | — | Windows Networking Denial of Service Vulnerability |
| CVE-2020-20212 | 6.5 | 83.1 | — | — |
| CVE-2024-38232 | 7.5 | 82.8 | — | Windows Networking Denial of Service Vulnerability |
| CVE-2024-21356 | 6.5 | 80.8 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2026-3238 | 7.5 | 80.3 | — | Samba: denial of service against ad dc wins server |
| CVE-2023-21700 | 7.5 | 75.7 | — | Windows iSCSI Discovery Service Denial of Service Vulnerability |
| CVE-2024-27053 | 8.8 | 75.7 | — | wifi: wilc1000: fix RCU usage in connect path |
| CVE-2026-63076 | 7.5 | 75.0 | — | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg |
| CVE-2026-20875 | 7.5 | 74.4 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-21243 | 7.5 | 72.0 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2026-38999 | 7.5 | 71.6 | — | — |
| CVE-2025-38191 | 5.5 | 70.0 | — | ksmbd: fix null pointer dereference in destroy_previous_session |
| CVE-2026-1584 | 7.5 | 69.9 | — | Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder |
| CVE-2026-32071 | 7.5 | 66.4 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-40405 | 7.5 | 66.4 | — | Windows TCP/IP Denial of Service Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 466 |
| microsoft | 42 |
| adobe | 20 |
| red hat | 19 |
| gnu | 14 |
| zephyrproject | 12 |
| ibm | 10 |
| nvidia | 8 |
| mongodb | 7 |
| openssl | 7 |
| wireshark foundation | 7 |
| apache | 6 |
| envoyproxy | 6 |
| apple | 5 |
| free5gc | 5 |