Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-480
Weakness type CWE-480 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 6 | 6 | 0 |
Monthly trend
▅▅█▅▅▁
2026-05 1 · 2026-06 1 · 2026-07 2 · 2026-08 1 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-63421 | 7.5 | 50.4 | — | Keystone: `graphql.maxTake` bypass with negative `take` |
| CVE-2026-48497 | 7.5 | 32.6 | — | Envoy: Abnormal process termination in DNS UDP filter |
| CVE-2026-15043 | 9.8 | 30.6 | — | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL ope… |
| CVE-2026-43114 | 9.4 | 28.8 | — | netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry |
| CVE-2026-79643 | 7.3 | 24.3 | — | — |
| CVE-2026-44722 | 6.2 | 1.5 | — | pyzipper: Encryption bypass for small files encrypted with pyzipper |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| danifus | 1 |
| dell | 1 |
| envoyproxy | 1 |
| hmbrand | 1 |
| keystonejs | 1 |
| linux | 1 |