Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-476 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 637 | 373 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▁▂▂▁▂▁▂▁▂▂▂▂▁▂▂▁▁▁▁▁▁▅█▆▃
2025-09 16 · 2025-10 14 · 2025-11 0 · 2025-12 1 · 2026-01 3 · 2026-02 3 · 2026-03 2 · 2026-04 3 · 2026-05 85 · 2026-06 135 · 2026-07 100 · 2026-08 42
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21525 | 6.2 | 91.5 | KEV | Windows Remote Access Connection Manager Denial of Service Vulnerability |
| CVE-2025-22037 | 5.5 | 99.2 | — | ksmbd: fix null pointer dereference in alloc_preauth_hash() |
| CVE-2023-3866 | 5.5 | 95.1 | — | ksmbd: validate session id and tree id in the compound request |
| CVE-2024-21404 | 7.5 | 84.8 | — | .NET Denial of Service Vulnerability |
| CVE-2026-3238 | 7.5 | 84.5 | — | Samba: denial of service against ad dc wins server |
| CVE-2024-38233 | 7.5 | 83.0 | — | Windows Networking Denial of Service Vulnerability |
| CVE-2024-38232 | 7.5 | 82.0 | — | Windows Networking Denial of Service Vulnerability |
| CVE-2024-21356 | 6.5 | 80.0 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2023-21700 | 7.5 | 74.7 | — | Windows iSCSI Discovery Service Denial of Service Vulnerability |
| CVE-2024-27053 | 8.8 | 74.4 | — | wifi: wilc1000: fix RCU usage in connect path |
| CVE-2026-20875 | 7.5 | 73.7 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-57875 | 7.5 | 71.1 | — | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing |
| CVE-2026-21243 | 7.5 | 69.0 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2026-59132 | 7.5 | 68.4 | — | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-42764 | 7.5 | 64.8 | — | NULL Pointer Dereference in QUIC Server Initial Packet Handling |
| CVE-2025-38191 | 5.5 | 63.5 | — | ksmbd: fix null pointer dereference in destroy_previous_session |
| CVE-2026-40405 | 7.5 | 62.4 | — | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-42766 | 5.9 | 61.9 | — | Possible NULL Dereference in Password-Based CMS Decryption |
| CVE-2026-32071 | 7.5 | 61.9 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-59138 | 6.5 | 61.4 | — | Microsoft Remote Registry Service Denial of Service Vulnerability |