Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-670
Weakness type CWE-670 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 26 | 23 | 0 |
Monthly trend
▂▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▃▇▃█▇▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 6 · 2026-07 2 · 2026-08 7 · 2026-09 6 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-53404 | 7.3 | 49.5 | — | Apache Tomcat: Bad ornext processing in RewriteValve |
| CVE-2026-55276 | 9.1 | 47.2 | — | Apache Tomcat: Logged effective web.xml is incomplete |
| CVE-2026-48844 | 7.5 | 41.3 | — | — |
| CVE-2026-20171 | 6.8 | 38.2 | — | Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability |
| CVE-2026-19487 | 5.3 | 33.9 | — | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match resul… |
| CVE-2026-55624 | 5.3 | 31.6 | — | MintyItanium Lost-Auction takes items like barrier blocks out from search GUI |
| CVE-2026-92932 | 5.1 | 30.7 | — | MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSR… |
| CVE-2026-56307 | 5.3 | 29.0 | — | Cap-go - Broken Cursor Pagination in /private/devices Endpoint |
| CVE-2026-16392 | 9.1 | 27.7 | — | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2026-56328 | 7.1 | 26.2 | — | Capgo - Integrity Issue in Release Routing via Multiple Public Channels |
| CVE-2026-7656 | 6.8 | 23.7 | — | Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Z… |
| CVE-2026-73468 | 7.1 | 19.6 | — | Security Advisory 0175 |
| CVE-2024-47745 | 7.8 | 19.2 | — | mm: call the security_mmap_file() LSM hook in remap_file_pages() |
| CVE-2026-96760 | 9.8 | 18.4 | — | Authlib library contains a signature‑verification bypass vulnerability |
| CVE-2026-102110 | 5.9 | 13.3 | — | Missing authentication on a Kiteworks appliance setup function |
| CVE-2022-49393 | 5.5 | 13.0 | — | misc: fastrpc: fix list iterator in fastrpc_req_mem_unmap_impl |
| CVE-2026-14935 | 3.7 | 12.8 | — | Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerpr… |
| CVE-2025-38291 | 5.5 | 10.1 | — | wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash |
| CVE-2026-102124 | 6.5 | 9.8 | — | Kiteworks Core Missing Authentication for Critical Function |
| CVE-2026-72703 | 6.8 | 6.5 | — | Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint via Unchec… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 4 |
| rocq-prover | 3 |
| apache | 2 |
| kiteworks | 2 |
| mozilla | 2 |
| arista networks | 1 |
| authlib | 1 |
| cap-go | 1 |
| capgo | 1 |
| cisco | 1 |
| mintyitanium | 1 |
| misp | 1 |
| openbsd | 1 |
| red hat | 1 |
| roundcube | 1 |