Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-617 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 99 | 88 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▆▃
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 10 · 2026-06 36 · 2026-07 28 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-5946 | 7.5 | 77.7 | — | Invalid handling of CLASS != IN |
| CVE-2026-41523 | 7.5 | 52.0 | — | vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows … |
| CVE-2025-15684 | 5.5 | 50.7 | — | Open5GS CER init.c diam_log_func assertion |
| CVE-2024-35884 | 5.5 | 49.6 | — | udp: do not accept non-tunnel GSO skbs landing in a tunnel |
| CVE-2023-52887 | 5.5 | 49.2 | — | net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rt… |
| CVE-2026-37228 | 7.5 | 48.0 | — | — |
| CVE-2026-37229 | 7.5 | 47.2 | — | — |
| CVE-2022-49325 | 5.5 | 47.1 | — | tcp: add accessors to read/set tp->snd_cwnd |
| CVE-2026-45815 | 7.5 | 46.2 | — | Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler |
| CVE-2026-12413 | 7.5 | 46.0 | — | IKEv2 Denial of Service via malformed fragmentation |
| CVE-2026-52954 | 7.5 | 42.2 | — | libceph: handle rbtree insertion error in decode_choose_args() |
| CVE-2026-13204 | 7.5 | 41.3 | — | Unexpected exit in certain situations with NSEC and NSEC3 both present |
| CVE-2026-12617 | 7.5 | 40.1 | — | Record ordering based unexpected exit with CNAME or DNAME |
| CVE-2026-37233 | 7.5 | 37.8 | — | — |
| CVE-2026-37223 | 7.5 | 36.6 | — | — |
| CVE-2026-52829 | 7.5 | 36.1 | — | ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book |
| CVE-2026-37222 | 7.5 | 35.9 | — | — |
| CVE-2026-37224 | 7.5 | 35.9 | — | — |
| CVE-2026-37225 | 7.5 | 34.8 | — | — |
| CVE-2026-37227 | 7.5 | 34.8 | — | — |
| Vendor | CVEs |
|---|---|
| linux | 27 |
| mongodb | 12 |
| isc | 4 |
| the libreswan project | 3 |
| dahua | 2 |
| free5gc | 2 |
| ggml-org | 2 |
| nimiq | 2 |
| openvpn | 2 |
| red hat | 2 |
| silicon labs | 2 |
| strukturag | 2 |
| vllm-project | 2 |
| zephyrproject | 2 |
| apache | 1 |