Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-770 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 447 | 414 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▇
2025-09 5 · 2025-10 1 · 2025-11 0 · 2025-12 2 · 2026-01 7 · 2026-02 1 · 2026-03 3 · 2026-04 7 · 2026-05 34 · 2026-06 99 · 2026-07 144 · 2026-08 119
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48933 | 7.5 | 88.9 | — | — |
| CVE-2026-42198 | 7.5 | 87.4 | — | pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS |
| CVE-2026-45591 | 7.5 | 82.9 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2025-9784 | 7.5 | 82.1 | — | Undertow: undertow madeyoureset http/2 ddos vulnerability |
| CVE-2024-43567 | 7.5 | 82.0 | — | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2025-61726 | 7.5 | 78.6 | — | Memory exhaustion in query parameter parsing in net/url |
| CVE-2026-45112 | 6.9 | 78.5 | — | Apache Thrift: Unbounded Read Leading to Denial of Service |
| CVE-2024-12254 | 8.7 | 77.8 | — | Unbounded memory buffering in SelectorSocketTransport.writelines() |
| CVE-2026-1519 | 7.5 | 73.8 | — | Excessive NSEC3 iterations cause high CPU load during insecure delegation validation |
| CVE-2025-26682 | 7.5 | 72.9 | — | ASP.NET Core and Visual Studio Denial of Service Vulnerability |
| CVE-2026-54113 | 7.5 | 63.7 | — | Remote Procedure Call Denial of Service Vulnerability |
| CVE-2026-33871 | 8.7 | 63.7 | — | Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass |
| CVE-2026-55968 | 8.7 | 63.0 | — | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-58389 | 8.7 | 63.0 | — | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-45292 | 5.3 | 63.0 | — | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation |
| CVE-2026-3039 | 7.5 | 61.5 | — | BIND 9 server memory exhaustion during GSS-API TKEY negotiation |
| CVE-2026-47302 | 7.5 | 61.0 | — | .NET Denial of Service Vulnerability |
| CVE-2023-5379 | 7.5 | 60.6 | — | Undertow: ajp request closes connection exceeding maxrequestsize |
| CVE-2026-56170 | 7.5 | 60.3 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-42587 | 7.5 | 59.8 | — | Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snapp… |
| Vendor | CVEs |
|---|---|
| apache | 22 |
| linux | 20 |
| red hat | 16 |
| microsoft | 13 |
| netty | 13 |
| elastic | 11 |
| ibm | 11 |
| spring | 8 |
| erlang | 6 |
| go standard library | 6 |
| legion of the bouncy castle | 6 |
| elixir-mint | 5 |
| gitlab | 5 |
| open-telemetry | 5 |
| scriban | 5 |