Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-763
Weakness type CWE-763 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 18 | 0 |
Monthly trend
▂▁▂▁▃▁▁▁▁▂▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▂▃▄▃▄█▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 3 · 2026-07 2 · 2026-08 3 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-48431 | 7.5 | 63.9 | — | Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid po… |
| CVE-2026-9516 | 7.5 | 47.7 | — | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pr… |
| CVE-2025-11838 | 8.7 | 40.3 | — | WatchGuard Firebox iked Memory Corruption Vulnerability |
| CVE-2026-15718 | 4.3 | 39.9 | — | Invalid pointer in the JavaScript: WebAssembly component |
| CVE-2026-19315 | 9.3 | 37.5 | — | Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution |
| CVE-2026-74947 | 8.8 | 36.8 | — | Privilege escalation due to invalid pointer in the Graphics component |
| CVE-2026-74860 | 8.5 | 35.6 | — | Libxml2: double-free/uaf in libxml2 python bindings |
| CVE-2026-52993 | 9.8 | 32.3 | — | tipc: fix double-free in tipc_buf_append() |
| CVE-2026-84131 | 8.8 | 24.6 | — | Privilege escalation due to invalid pointer in the Graphics component |
| CVE-2026-77500 | 7.8 | 24.4 | — | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2022-49160 | 5.5 | 23.5 | — | scsi: qla2xxx: Fix crash during module load unload test |
| CVE-2024-42132 | 7.1 | 19.6 | — | bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX |
| CVE-2024-40979 | 5.5 | 17.2 | — | wifi: ath12k: fix kernel crash during resume |
| CVE-2026-88340 | 7.6 | 14.8 | — | — |
| CVE-2026-100813 | 8.8 | 14.5 | — | Invalid pointer in the JavaScript Engine: JIT component |
| CVE-2024-36890 | 5.5 | 13.4 | — | mm/slab: make __free(kfree) accept error pointers |
| CVE-2021-47087 | 7.8 | 13.3 | — | tee: optee: Fix incorrect page free bug |
| CVE-2024-56573 | 5.5 | 13.0 | — | efi/libstub: Free correct pointer on failure |
| CVE-2023-20511 | 6.4 | 12.9 | — | — |
| CVE-2026-53000 | 7.8 | 7.9 | — | netfilter: nat: use kfree_rcu to release ops |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 11 |
| mozilla | 4 |
| watchguard | 2 |
| amd | 1 |
| apache | 1 |
| asus | 1 |
| foxit software | 1 |
| microsoft | 1 |
| red hat | 1 |
| rurban | 1 |