Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-755
Weakness type CWE-755 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 52 | 41 | 3 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▁▂▂▁▁▁▂▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▆▂█▄
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 5 · 2026-07 10 · 2026-08 2 · 2026-09 13 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-5638 | 9.8 | 100.0 | KEV | Apache Struts |
| CVE-2020-7247 | 9.8 | 99.9 | KEV | OpenBSD OpenSMTPD |
| CVE-2021-38003 | 8.8 | 98.5 | KEV | Google Chromium V8 |
| CVE-2026-23666 | 7.5 | 70.1 | — | .NET Framework Denial of Service Vulnerability |
| CVE-2020-1071 | 6.8 | 62.4 | — | Windows Remote Access Common Dialog Elevation of Privilege Vulnerability |
| CVE-2026-89025 | 8.7 | 54.1 | — | Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request |
| CVE-2026-53459 | 9.3 | 53.7 | — | Bambuddy's authentication fails open on database errors, allowing unauthenticated acces… |
| CVE-2024-26584 | 5.5 | 53.0 | — | net: tls: handle backlogging of crypto requests |
| CVE-2026-54632 | 7.5 | 52.2 | — | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media s… |
| CVE-2026-44319 | 7.5 | 49.6 | — | free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-co… |
| CVE-2026-44325 | 7.5 | 49.6 | — | free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Ref… |
| CVE-2026-59162 | 6.9 | 49.6 | — | Excelize: Negative shared-string index causes panic in GetCellValue and GetRows |
| CVE-2024-6594 | 8.7 | 48.8 | — | WatchGuard Firebox Single Sign-On Client Denial-of-Service |
| CVE-2026-9516 | 7.5 | 47.7 | — | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pr… |
| CVE-2026-52856 | 7.5 | 47.3 | — | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser… |
| CVE-2026-81515 | 7.5 | 47.3 | — | Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry f… |
| CVE-2026-81516 | 7.5 | 47.3 | — | Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (… |
| CVE-2026-54775 | 6.5 | 46.8 | — | CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),… |
| CVE-2026-59927 | 5.3 | 42.8 | — | Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `… |
| CVE-2026-59952 | 6.9 | 42.4 | — | Valibot: record() issue paths can make flatten() throw for inherited Object property names |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 6 |
| linux | 5 |
| free5gc | 2 |
| jpadilla | 2 |
| microsoft | 2 |
| midnightbsd | 2 |
| nlnet labs | 2 |
| red hat | 2 |
| steeltoeoss | 2 |
| trusted domain project | 2 |
| @opentelemetry | 1 |
| ag-ui-protocol | 1 |
| belden | 1 |
| coredns | 1 |
| corewcf | 1 |