Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-755 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 31 | 24 | 0 |
▂▁▁▂▁▂▂▁▁▁▂▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▅█▂
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 6 · 2026-07 10 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-23666 | 7.5 | 68.8 | — | .NET Framework Denial of Service Vulnerability |
| CVE-2024-26584 | 5.5 | 52.0 | — | net: tls: handle backlogging of crypto requests |
| CVE-2024-6594 | 8.7 | 47.6 | — | WatchGuard Firebox Single Sign-On Client Denial-of-Service |
| CVE-2026-40371 | 8.8 | 47.5 | — | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-59952 | 6.9 | 42.3 | — | Valibot: record() issue paths can make flatten() throw for inherited Object property names |
| CVE-2022-48673 | 5.5 | 41.0 | — | net/smc: Fix possible access to freed memory in link clear |
| CVE-2026-44902 | 7.5 | 37.9 | — | opentelemetry-js: Prometheus exporter process crash via malformed HTTP request |
| CVE-2026-42792 | 6.3 | 36.9 | — | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-44319 | 7.5 | 33.8 | — | free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co… |
| CVE-2026-44325 | 7.5 | 32.7 | — | free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Ref… |
| CVE-2026-59162 | 6.9 | 32.3 | — | Excelize: Negative shared-string index causes panic in GetCellValue and GetRows |
| CVE-2026-45819 | 6.6 | 30.4 | — | — |
| CVE-2026-49235 | 8.7 | 30.0 | — | Routinator crashes on specifically crafted RRDP XML files |
| CVE-2026-9516 | 7.5 | 29.3 | — | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pr… |
| CVE-2026-59927 | 5.3 | 28.4 | — | Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `… |
| CVE-2026-49232 | 8.7 | 27.3 | — | Routinator exits when accepting an incoming HTTP or RTR connection fails |
| CVE-2026-54775 | 6.5 | 26.6 | — | CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),… |
| CVE-2026-48524 | 3.7 | 26.6 | — | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values … |
| CVE-2026-52856 | 7.5 | 26.5 | — | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser… |
| CVE-2024-50001 | 5.5 | 25.6 | — | net/mlx5: Fix error path in multi-packet WQE transmit |
| Vendor | CVEs |
|---|---|
| linux | 5 |
| free5gc | 2 |
| microsoft | 2 |
| nlnet labs | 2 |
| red hat | 2 |
| @opentelemetry | 1 |
| coredns | 1 |
| corewcf | 1 |
| erlang | 1 |
| huawei | 1 |
| imagemagick | 1 |
| jpadilla | 1 |
| kerberosmansour | 1 |
| lepture | 1 |
| nimiq | 1 |