Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-617
Weakness type CWE-617 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 159 | 147 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▅▄█▁
2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 11 · 2026-06 36 · 2026-07 28 · 2026-08 20 · 2026-09 44 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-13878 | 7.5 | 95.2 | — | Malformed BRID/HHIT records can cause named to terminate unexpectedly |
| CVE-2020-20211 | 6.5 | 84.4 | — | — |
| CVE-2026-5946 | 7.5 | 76.4 | — | Invalid handling of CLASS != IN |
| CVE-2026-45815 | 7.5 | 62.5 | — | Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler |
| CVE-2026-41523 | 7.5 | 58.7 | — | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows … |
| CVE-2026-27135 | 7.5 | 58.0 | — | nghttp2 Denial of service: Assertion failure due to the missing state validation |
| CVE-2025-15684 | 5.5 | 53.0 | — | Open5GS CER init.c diam_log_func assertion |
| CVE-2026-90785 | 5.5 | 52.4 | — | Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion |
| CVE-2026-90786 | 5.5 | 52.4 | — | Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion |
| CVE-2026-52954 | 7.5 | 52.1 | — | libceph: handle rbtree insertion error in decode_choose_args() |
| CVE-2026-52718 | 6.5 | 51.9 | — | Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser … |
| CVE-2026-92971 | 8.7 | 51.7 | — | InternLM LMDeploy through 0.17.0 Assertion Denial of Service |
| CVE-2026-86317 | 6.9 | 51.6 | — | ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion |
| CVE-2024-35884 | 5.5 | 51.0 | — | udp: do not accept non-tunnel GSO skbs landing in a tunnel |
| CVE-2026-76163 | 7.5 | 50.3 | — | named aborts on a TKEY query when the user configuration has no global options statement |
| CVE-2023-52887 | 5.5 | 50.3 | — | net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rt… |
| CVE-2026-55514 | 7.1 | 50.0 | — | vLLM denial of service via prompt embeds on M-RoPE models |
| CVE-2026-44319 | 7.5 | 49.6 | — | free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co… |
| CVE-2022-49325 | 5.5 | 49.1 | — | tcp: add accessors to read/set tp->snd_cwnd |
| CVE-2026-37228 | 7.5 | 48.8 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 28 |
| mongodb | 18 |
| isc | 7 |
| pexip | 4 |
| red hat | 4 |
| the libreswan project | 4 |
| freerdp | 3 |
| ggml-org | 3 |
| strukturag | 3 |
| vllm-project | 3 |
| zcashfoundation | 3 |
| zephyrproject | 3 |
| dahua | 2 |
| dvidelabs | 2 |
| free5gc | 2 |