Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-676
Weakness type CWE-676 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 4 | 4 | 0 |
Monthly trend
▅▁█▅▁▁
2026-05 1 · 2026-06 0 · 2026-07 2 · 2026-08 1 · 2026-09 0 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-14601 | 8.6 | 63.4 | — | vsDesk Task Scheduler OS Command Injection |
| CVE-2026-54499 | 7.5 | 42.0 | — | Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders |
| CVE-2026-14501 | 9.8 | 37.6 | — | Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub |
| CVE-2026-48696 | 6.2 | 6.4 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 1 |
| stanfordnlp | 1 |
| vsdesk | 1 |