Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-703 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 17 | 0 |
▂▁▂▁▁▄▅█
2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 4 · 2026-08 8
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21720 | 7.5 | 46.9 | — | Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out |
| CVE-2026-44893 | 7.5 | 46.9 | — | Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length |
| CVE-2026-56818 | 6.5 | 38.6 | — | Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state |
| CVE-2026-51600 | 7.5 | 33.8 | — | — |
| CVE-2025-59322 | 7.5 | 29.3 | — | — |
| CVE-2026-18638 | 6.5 | 21.5 | — | Velociraptor server crash via the SetPassword API |
| CVE-2026-56338 | 6.9 | 20.7 | — | Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint |
| CVE-2026-20187 | 7.5 | 19.0 | — | Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities |
| CVE-2026-12324 | 7.3 | 11.3 | — | Incorrect boundary conditions in the Graphics: CanvasWebGL component |
| CVE-2026-65331 | 4.3 | 10.4 | — | — |
| CVE-2026-65332 | 4.3 | 10.4 | — | — |
| CVE-2026-65337 | 4.3 | 10.4 | — | — |
| CVE-2026-65340 | 4.3 | 10.4 | — | — |
| CVE-2026-16218 | 2.1 | 10.2 | — | hunvreus devpush Storage Reset Failure storage.py reset_storage improper check or handl… |
| CVE-2026-65351 | 4.3 | 9.6 | — | — |
| CVE-2026-38763 | 5.5 | 7.5 | — | — |
| CVE-2026-0011 | 8.4 | 1.7 | — | — |