Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-672 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 11 | 0 |
▃▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▃▁▃▁▁▁▁▁▁▁█▆██
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 2 · 2026-07 3 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33278 | 9.1 | 67.6 | — | Possible arbitrary code execution during DNSSEC validation |
| CVE-2026-58291 | 6.1 | 45.5 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-56314 | 7.1 | 35.7 | — | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
| CVE-2026-68481 | 7.5 | 35.7 | — | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider |
| CVE-2026-52733 | 6.5 | 26.5 | — | ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork … |
| CVE-2026-42791 | 6.3 | 24.4 | — | OCSP responder certificate validity period not checked in public_key |
| CVE-2021-47069 | 7.0 | 18.0 | — | ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry |
| CVE-2024-57929 | 7.1 | 17.2 | — | dm array: fix releasing a faulty array block twice in dm_array_cursor_end |
| CVE-2026-33463 | 5.3 | 15.1 | — | Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthoriz… |
| CVE-2026-2379 | 8.2 | 13.6 | — | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay i… |
| CVE-2026-42955 | 3.7 | 10.6 | — | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-… |
| CVE-2025-39698 | 5.5 | 9.2 | — | io_uring/futex: ensure io_futex_wait() cleans up properly on failure |
| CVE-2026-47087 | 3.5 | 9.2 | — | — |
| CVE-2025-38290 | 5.5 | 8.7 | — | wifi: ath12k: fix node corruption in ar->arvifs list |
| CVE-2026-50575 | 7.7 | 6.9 | — | BetterDesk has a replay behavior vulnerability when devices are deleted |
| Vendor | CVEs |
|---|---|
| linux | 4 |
| nlnet labs | 2 |
| apache | 1 |
| arista networks | 1 |
| capgo | 1 |
| cyrusimap | 1 |
| elastic | 1 |
| erlang | 1 |
| microsoft | 1 |
| unitronix | 1 |
| zcashfoundation | 1 |