Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-680
Weakness type CWE-680 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
▃▃▁█▆▁
2026-05 1 · 2026-06 1 · 2026-07 0 · 2026-08 4 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55200 | 9.2 | 56.1 | — | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c |
| CVE-2026-76825 | 8.4 | 48.3 | — | RestrictedPython: Sandbox escape via string.Formatter field resolution |
| CVE-2026-8376 | 9.8 | 39.5 | — | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43… |
| CVE-2026-19313 | 9.3 | 38.8 | — | Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution |
| CVE-2026-81647 | 5.3 | 27.8 | — | — |
| CVE-2026-19588 | 6.5 | 26.8 | — | — |
| CVE-2026-90783 | 8.5 | 9.2 | — | MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wrapar… |
| CVE-2026-43627 | 8.5 | 9.1 | — | llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function |
| CVE-2026-70651 | 6.9 | 4.6 | — | libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ggml-org | 1 |
| huawei | 1 |
| libssh2 | 1 |
| libvips | 1 |
| moritz bunkus | 1 |
| samsung open source | 1 |
| watchguard | 1 |
| zopefoundation | 1 |