Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-704 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 15 | 0 |
▂▁▁▁▁▂▁▁▁▁▁▁▁▃▅▆█
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 3 · 2026-07 4 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-15826 | 9.8 | 53.9 | — | User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusi… |
| CVE-2026-46597 | 7.5 | 39.1 | — | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh |
| CVE-2026-45685 | 7.5 | 38.4 | — | OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages |
| CVE-2026-48140 | 7.1 | 37.2 | — | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream |
| CVE-2025-51678 | 7.5 | 36.1 | — | — |
| CVE-2026-44324 | 6.5 | 35.2 | — | free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf… |
| CVE-2026-59871 | 7.5 | 34.3 | — | node-tar: Process crash via PAX numeric path type confusion |
| CVE-2026-18675 | 5.3 | 31.7 | — | Kong Mesh: control plane denial of service via a malformed dataplane token with a non-s… |
| CVE-2026-50337 | 7.8 | 23.8 | — | Windows Notification Elevation of Privilege Vulnerability |
| CVE-2026-55076 | 7.4 | 23.5 | — | Coder's OIDC email_verified type coercion bypass enables account takeover via unverifie… |
| CVE-2025-39880 | 7.8 | 22.8 | — | libceph: fix invalid accesses to ceph_connection_v1_info |
| CVE-2026-10080 | 6.5 | 22.2 | — | Boards plugin panics on WebSocket command with non-string field types |
| CVE-2026-73429 | 5.3 | 21.7 | — | Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) |
| CVE-2026-53798 | 6.9 | 20.3 | — | rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping |
| CVE-2025-22044 | 5.5 | 10.4 | — | acpi: nfit: fix narrowing conversion in acpi_nfit_ctl |
| CVE-2026-6726 | 7.9 | 5.9 | — | An information leakage vulnerability in the TCG TPM 2.0 reference code. |
| CVE-2026-46690 | 5.8 | 3.1 | — | unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc dr… |
| Vendor | CVEs |
|---|---|
| linux | 2 |
| coder | 1 |
| cozmoslabs | 1 |
| eugeny | 1 |
| free5gc | 1 |
| golang.org/x/crypto | 1 |
| isaacs | 1 |
| kong | 1 |
| mattermost | 1 |
| microsoft | 1 |
| ni | 1 |
| open-telemetry | 1 |
| rsyncproject | 1 |
| spearman | 1 |
| trusted computing group | 1 |