Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-628
Weakness type CWE-628 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 4 | 4 | 0 |
Monthly trend
▅▁▁▅▁█
2026-05 1 · 2026-06 0 · 2026-07 0 · 2026-08 1 · 2026-09 0 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-19349 | 9.8 | 55.8 | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, fro… |
| CVE-2026-94636 | 8.2 | 34.8 | — | Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once… |
| CVE-2026-104430 | 8.7 | 33.1 | — | Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount |
| CVE-2026-43133 | 7.9 | 2.4 | — | KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 1 |
| linux | 1 |
| zcashfoundation | 1 |