Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-682
Weakness type CWE-682 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 24 | 21 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▁▁▂▁▄▂▄▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 3 · 2026-08 6 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-71479 | 9.1 | 49.2 | — | New API: Integer overflow in quota billing yields negative charges (self-crediting) |
| CVE-2025-4435 | 7.5 | 46.3 | — | Tarfile extracts filtered members when errorlevel=0 |
| CVE-2026-53670 | 9.3 | 41.1 | — | PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pas… |
| CVE-2026-53671 | 9.3 | 41.1 | — | PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verifi… |
| CVE-2026-53706 | 8.8 | 41.1 | — | PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PAS… |
| CVE-2026-47247 | 7.5 | 39.2 | — | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pi… |
| CVE-2026-20270 | 8.6 | 38.3 | — | Cisco IOS XE Software Security Hardening Release |
| CVE-2025-5372 | 8.8 | 38.2 | — | Libssh: incorrect return code handling in ssh_kdf() in libssh |
| CVE-2026-10512 | 2.3 | 37.0 | — | X25519 x86_64 assembly final reduction leaves non-canonical field element |
| CVE-2026-16363 | 9.8 | 35.7 | — | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-54754 | 9.6 | 35.3 | — | Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid … |
| CVE-2026-33487 | 7.5 | 33.9 | — | goxmldsig has validateSignature Loop Variable Capture Signature Bypass |
| CVE-2026-76043 | 8.8 | 33.3 | — | — |
| CVE-2026-44074 | 3.7 | 30.8 | — | Bitwise OR of errno values |
| CVE-2026-86736 | 5.3 | 20.4 | — | snipe-it before 8.7.0 Checkout Request Counter Integrity Failure |
| CVE-2026-20335 | 8.1 | 18.7 | — | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Softw… |
| CVE-2026-7836 | 3.1 | 18.4 | — | hextoint macro uppercase bug |
| CVE-2026-10773 | 5.4 | 16.8 | — | Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) |
| CVE-2026-18459 | 8.7 | 15.2 | — | Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows… |
| CVE-2024-41011 | 7.8 | 11.8 | — | drm/amdkfd: don't allow mapping the MMIO HDP page with large pages |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| cisco | 3 |
| vbpf | 3 |
| netatalk | 2 |
| 1 | |
| grokability | 1 |
| imagemagick | 1 |
| klever-io | 1 |
| ledger | 1 |
| libssh | 1 |
| linux | 1 |
| mozilla | 1 |
| python software foundation | 1 |
| quantumnous | 1 |
| red hat | 1 |
| rti | 1 |