Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-704
Weakness type CWE-704 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 23 | 0 |
Monthly trend
▂▁▁▁▁▂▁▁▁▁▁▁▁▃▄▅█▇▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 3 · 2026-07 4 · 2026-08 7 · 2026-09 6 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-15826 | 9.8 | 90.0 | — | User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusi… |
| CVE-2026-44324 | 6.5 | 51.4 | — | free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf… |
| CVE-2026-59871 | 7.5 | 49.1 | — | node-tar: Process crash via PAX numeric path type confusion |
| CVE-2026-45685 | 7.5 | 48.5 | — | OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages |
| CVE-2026-46597 | 7.5 | 47.9 | — | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh |
| CVE-2026-55076 | 7.4 | 47.4 | — | Coder's OIDC email_verified type coercion bypass enables account takeover via unverifie… |
| CVE-2025-51678 | 7.5 | 47.3 | — | — |
| CVE-2026-18675 | 5.3 | 44.7 | — | Kong Mesh: control plane denial of service via a malformed dataplane token with a non-s… |
| CVE-2026-73429 | 5.3 | 41.1 | — | Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) |
| CVE-2026-50278 | 6.5 | 37.1 | — | iccDEV: CIccEmbedIO::Read8() size_t underflow |
| CVE-2026-48140 | 7.1 | 36.5 | — | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream |
| CVE-2026-53798 | 6.9 | 34.9 | — | rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping |
| CVE-2026-10080 | 6.5 | 34.1 | — | Boards plugin panics on WebSocket command with non-string field types |
| CVE-2026-20249 | 8.6 | 31.8 | — | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense So… |
| CVE-2026-58822 | 9.8 | 29.9 | — | — |
| CVE-2026-28609 | 8.8 | 28.8 | — | — |
| CVE-2026-86348 | 4.3 | 27.4 | — | MS Calendar plugin: unrecovered handler panics from malformed post-action requests coul… |
| CVE-2026-50337 | 7.8 | 24.4 | — | Windows Notification Elevation of Privilege Vulnerability |
| CVE-2026-69585 | 7.8 | 24.4 | — | Microsoft Windows Search Component Elevation of Privilege Vulnerability |
| CVE-2025-39880 | 7.8 | 23.1 | — | libceph: fix invalid accesses to ceph_connection_v1_info |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 3 | |
| linux | 2 |
| mattermost | 2 |
| microsoft | 2 |
| cisco | 1 |
| coder | 1 |
| cozmoslabs | 1 |
| eugeny | 1 |
| free5gc | 1 |
| golang.org/x/crypto | 1 |
| internationalcolorconsortium | 1 |
| isaacs | 1 |
| kong | 1 |
| ni | 1 |
| open-telemetry | 1 |