Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-674
Weakness type CWE-674 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 195 | 185 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▅▅▇█▂
2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 4 · 2026-04 3 · 2026-05 10 · 2026-06 32 · 2026-07 29 · 2026-08 46 · 2026-09 50 · 2026-10 8
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-5971 | 7.5 | 86.6 | — | Undertow: response write hangs in case of java 17 tlsv1.3 newsessionticket |
| CVE-2024-8176 | 7.5 | 70.0 | — | Libexpat: expat: improper restriction of xml entity expansion depth in libexpat |
| CVE-2026-49451 | 7.5 | 68.1 | — | Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing |
| CVE-2026-69378 | 7.5 | 66.4 | — | Microsoft Exchange Server Denial of Service Vulnerability |
| CVE-2026-41606 | 5.3 | 64.5 | — | Apache Thrift: c_glib dispatch stack overflow |
| CVE-2026-61483 | 7.5 | 62.5 | — | Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow… |
| CVE-2022-37315 | 7.5 | 62.0 | — | — |
| CVE-2026-32141 | 7.5 | 61.3 | — | flatted: Unbounded recursion DoS in parse() revive phase |
| CVE-2026-0990 | 5.9 | 60.6 | — | Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing |
| CVE-2026-42039 | 6.9 | 60.4 | — | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data |
| CVE-2026-61551 | 8.6 | 59.6 | — | Icinga 2: Stack overflow via deeply nested JSON objects |
| CVE-2026-30922 | 7.5 | 59.3 | — | pyasn1 Vulnerable to Denial of Service via Unbounded Recursion |
| CVE-2026-93450 | 8.7 | 58.8 | — | go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal … |
| CVE-2026-41673 | 8.7 | 57.7 | — | xmldom: Denial of service via uncontrolled recursion in XML serialization |
| CVE-2026-66274 | 7.5 | 54.2 | — | Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-67552 | 7.5 | 54.2 | — | Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stacko… |
| CVE-2026-67590 | 7.5 | 54.2 | — | Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-68073 | 7.5 | 54.2 | — | Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow |
| CVE-2026-15996 | 6.6 | 53.9 | — | Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated ser… |
| CVE-2026-15830 | 6.9 | 53.8 | — | Potential denial-of-service vulnerability via nested geometry collections |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 22 |
| linux | 14 |
| elastic | 8 |
| ibm | 7 |
| red hat | 7 |
| scriban | 5 |
| surrealdb | 5 |
| imagemagick | 4 |
| messagepack-csharp | 4 |
| qt | 4 |
| autodesk | 3 |
| legion of the bouncy castle | 3 |
| protobufjs | 3 |
| samsung open source | 3 |
| amazon | 2 |