Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-664
Weakness type CWE-664 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 13 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▁▃▆█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 0 · 2026-07 2 · 2026-08 4 · 2026-09 6 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-27518 | 9.8 | 93.7 | KEV | Unauthenticated remote arbitrary code execution |
| CVE-2026-43503 | 8.8 | 79.9 | — | net: skbuff: propagate shared-frag marker through frag-transfer helpers |
| CVE-2026-20274 | 9.8 | 52.7 | — | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2025-34226 | 7.1 | 49.9 | — | OpenPLC Runtime v3 Persistent DoS |
| CVE-2026-18549 | 7.5 | 47.0 | — | @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit |
| CVE-2026-54251 | 8.7 | 41.1 | — | netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decry… |
| CVE-2026-20269 | 8.6 | 38.3 | — | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20158 | 7.5 | 38.3 | — | Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities |
| CVE-2026-20353 | 9.8 | 31.5 | — | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-79603 | 4.3 | 27.6 | — | Unconditionally do TLB flushing ahead of page scrubbing |
| CVE-2026-86203 | 6.3 | 26.1 | — | PocketMine-MP before 5.39.2 Item Duplication via Despawn State |
| CVE-2026-79289 | 3.1 | 18.2 | — | — |
| CVE-2026-20336 | 8.8 | 8.5 | — | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Softw… |
| CVE-2026-19380 | 1.8 | 5.5 | — | Mullvad wireguard.sys IOCTL AdapterState reference count |
| CVE-2026-64721 | 5.5 | 5.0 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| cisco | 5 |
| @fastify/multipart | 1 |
| apple | 1 |
| autonomy logic | 1 |
| citrix | 1 |
| 1 | |
| io.netty.incubator | 1 |
| linux | 1 |
| mullvad | 1 |
| netty | 1 |
| pmmp | 1 |
| xen | 1 |