Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-672
Weakness type CWE-672 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 19 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▂▁▁▁▁▁▁▁▅▃▅█▇▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 2 · 2026-07 3 · 2026-08 6 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33278 | 9.1 | 65.3 | — | Possible arbitrary code execution during DNSSEC validation |
| CVE-2026-58291 | 6.1 | 61.3 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-55250 | 8.7 | 57.4 | — | Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta… |
| CVE-2026-68481 | 7.5 | 50.0 | — | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider |
| CVE-2026-61699 | 8.1 | 36.5 | — | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-52733 | 6.5 | 35.6 | — | ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork … |
| CVE-2026-56314 | 7.1 | 34.6 | — | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
| CVE-2026-33463 | 5.3 | 30.6 | — | Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthoriz… |
| CVE-2026-44725 | 6.6 | 28.8 | — | EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code exe… |
| CVE-2026-53637 | 6.5 | 27.8 | — | Sylius: Cart FormComponent allows modification or deletion of an already-completed order |
| CVE-2026-42791 | 6.3 | 22.9 | — | OCSP responder certificate validity period not checked in public_key |
| CVE-2026-85044 | 6.5 | 21.2 | — | — |
| CVE-2026-47087 | 3.5 | 19.2 | — | — |
| CVE-2026-95366 | 6.5 | 19.1 | — | — |
| CVE-2026-79010 | 4.3 | 18.0 | — | — |
| CVE-2021-47069 | 7.0 | 16.5 | — | ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry |
| CVE-2024-57929 | 7.1 | 16.1 | — | dm array: fix releasing a faulty array block twice in dm_array_cursor_end |
| CVE-2026-19538 | 8.2 | 12.8 | — | Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS |
| CVE-2026-2379 | 8.2 | 12.1 | — | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay i… |
| CVE-2025-38290 | 5.5 | 11.8 | — | wifi: ath12k: fix node corruption in ar->arvifs list |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 4 |
| 3 | |
| nlnet labs | 3 |
| apache | 1 |
| arista networks | 1 |
| capgo | 1 |
| cyrusimap | 1 |
| elastic | 1 |
| emqx | 1 |
| erlang | 1 |
| forgekeep | 1 |
| macropay-solutions | 1 |
| microsoft | 1 |
| sylius | 1 |
| unitronix | 1 |