Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-703
Weakness type CWE-703 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 32 | 29 | 3 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▁▃▅█▇▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 5 · 2026-08 10 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-25370 | 6.1 | 58.0 | KEV | Samsung Mobile Devices |
| CVE-2021-25372 | 6.1 | 55.2 | KEV | Samsung Mobile Devices |
| CVE-2022-22265 | 5.0 | 31.0 | KEV | Samsung Mobile Devices |
| CVE-2026-32641 | 7.5 | 59.0 | — | Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middle… |
| CVE-2026-44893 | 7.5 | 57.7 | — | Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length |
| CVE-2026-21720 | 7.5 | 51.6 | — | Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out |
| CVE-2026-71640 | 9.1 | 48.5 | — | — |
| CVE-2026-71645 | 7.5 | 47.3 | — | — |
| CVE-2026-51600 | 7.5 | 45.4 | — | — |
| CVE-2026-61822 | 6.5 | 42.8 | — | pg_partman disable maintenance for all partition sets |
| CVE-2026-92790 | 6.9 | 41.9 | — | Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header |
| CVE-2025-59322 | 7.5 | 40.1 | — | — |
| CVE-2026-56338 | 6.9 | 40.1 | — | Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint |
| CVE-2026-26446 | 7.5 | 39.8 | — | — |
| CVE-2026-56818 | 6.5 | 38.7 | — | Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state |
| CVE-2026-20187 | 7.5 | 38.3 | — | Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities |
| CVE-2026-13753 | 7.5 | 37.6 | — | Certain HP DeskJet All in One – Potential Information Disclosure |
| CVE-2026-65331 | 4.3 | 37.3 | — | — |
| CVE-2026-65332 | 4.3 | 37.3 | — | — |
| CVE-2026-65337 | 4.3 | 37.3 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apple | 5 |
| cisco | 3 |
| samsung mobile | 3 |
| netty | 2 |
| 1hive | 1 |
| capgo | 1 |
| dell | 1 |
| 1 | |
| grafana | 1 |
| higress-group | 1 |
| hp | 1 |
| hunvreus | 1 |
| ljharb | 1 |
| mozilla | 1 |
| parseablehq | 1 |