Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-606 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 19 | 0 |
▂▁▇▆▅█
2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 4 · 2026-07 3 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-1519 | 7.5 | 73.8 | — | Excessive NSEC3 iterations cause high CPU load during insecure delegation validation |
| CVE-2026-62901 | 7.5 | 61.8 | — | .NET Denial of Service Vulnerability |
| CVE-2026-39820 | 7.5 | 53.2 | — | Quadratic string concatentation in consumeComment in net/mail |
| CVE-2026-33814 | 7.5 | 53.1 | — | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/in… |
| CVE-2026-42561 | 7.5 | 51.8 | — | Python-Multipart: Denial of Service via unbounded multipart part headers |
| CVE-2026-5950 | 5.3 | 48.8 | — | Unbounded resend loop in BIND 9 resolver |
| CVE-2026-27145 | 6.5 | 45.7 | — | Inefficient candidate hostname parsing in crypto/x509 |
| CVE-2026-44289 | 7.5 | 45.1 | — | protobufjs: Denial of service through unbounded protobuf recursion |
| CVE-2026-10143 | 8.7 | 41.8 | — | kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py |
| CVE-2026-11972 | 8.2 | 37.2 | — | tarfile opened in streaming mode mishandles EOF |
| CVE-2026-66276 | 6.5 | 35.4 | — | Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service |
| CVE-2026-68077 | 6.5 | 35.4 | — | Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service |
| CVE-2026-67554 | 6.5 | 34.6 | — | Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of s… |
| CVE-2026-71439 | 5.3 | 32.4 | — | Mermaid radar diagrams are vulnerable to DoS |
| CVE-2026-20301 | 8.6 | 25.7 | — | Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of S… |
| CVE-2026-55731 | 6.6 | 25.1 | — | Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent |
| CVE-2026-33800 | 7.1 | 6.2 | — | Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause… |
| CVE-2026-15172 | 5.5 | 2.4 | — | Unchecked Input for Loop Condition in Wireshark |
| CVE-2026-41986 | 2.4 | 1.4 | — | — |
| Vendor | CVEs |
|---|---|
| apache | 3 |
| go standard library | 3 |
| isc | 2 |
| cisco | 1 |
| dana powers | 1 |
| golang.org/x/net | 1 |
| huawei | 1 |
| juniper networks | 1 |
| kludex | 1 |
| loytec | 1 |
| mermaid-js | 1 |
| microsoft | 1 |
| protobufjs | 1 |
| python software foundation | 1 |
| wireshark foundation | 1 |