Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-670 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 13 | 0 |
▂▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▃█▃▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 6 · 2026-07 2 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-53404 | 7.3 | 45.2 | — | Apache Tomcat: Bad ornext processing in RewriteValve |
| CVE-2026-55276 | 9.1 | 43.3 | — | Apache Tomcat: Logged effective web.xml is incomplete |
| CVE-2026-20171 | 6.8 | 38.7 | — | Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability |
| CVE-2026-19487 | 5.3 | 36.4 | — | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match resul… |
| CVE-2026-48844 | 7.5 | 34.7 | — | — |
| CVE-2026-56307 | 5.3 | 30.6 | — | Cap-go - Broken Cursor Pagination in /private/devices Endpoint |
| CVE-2026-16392 | 9.1 | 29.4 | — | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-7656 | 6.8 | 24.0 | — | Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Z… |
| CVE-2024-47745 | 7.8 | 21.2 | — | mm: call the security_mmap_file() LSM hook in remap_file_pages() |
| CVE-2026-56328 | 7.1 | 16.3 | — | Capgo - Integrity Issue in Release Routing via Multiple Public Channels |
| CVE-2022-49393 | 5.5 | 14.1 | — | misc: fastrpc: fix list iterator in fastrpc_req_mem_unmap_impl |
| CVE-2025-38291 | 5.5 | 9.7 | — | wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash |
| CVE-2026-12321 | 5.4 | 5.6 | — | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-14935 | 3.7 | 4.8 | — | Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverte… |
| CVE-2026-20713 | 4.5 | 1.1 | — | — |
| CVE-2026-73283 | 2.5 | 0.3 | — | — |