Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-770
Weakness type CWE-770 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 773 | 733 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▆▇█▂
2025-11 0 · 2025-12 3 · 2026-01 7 · 2026-02 1 · 2026-03 5 · 2026-04 12 · 2026-05 36 · 2026-06 98 · 2026-07 144 · 2026-08 187 · 2026-09 207 · 2026-10 36
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42198 | 7.5 | 90.5 | — | pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS |
| CVE-2026-48933 | 7.5 | 89.4 | — | — |
| CVE-2025-61726 | 7.5 | 82.9 | — | Memory exhaustion in query parameter parsing in net/url |
| CVE-2025-9784 | 7.5 | 82.9 | — | Undertow: undertow madeyoureset http/2 ddos vulnerability |
| CVE-2024-43567 | 7.5 | 82.8 | — | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2026-3039 | 7.5 | 82.6 | — | BIND 9 server memory exhaustion during GSS-API TKEY negotiation |
| CVE-2024-12254 | 8.7 | 78.6 | — | Unbounded memory buffering in SelectorSocketTransport.writelines() |
| CVE-2026-45769 | 7.5 | 77.6 | — | ikev2: unbounded client transform storage can lead to resource exhaustion |
| CVE-2025-26682 | 7.5 | 76.0 | — | ASP.NET Core and Visual Studio Denial of Service Vulnerability |
| CVE-2026-1519 | 7.5 | 74.9 | — | Excessive NSEC3 iterations cause high CPU load during insecure delegation validation |
| CVE-2026-45416 | 7.5 | 74.6 | — | Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes |
| CVE-2023-39533 | 7.5 | 73.4 | — | libp2p nodes vulnerable to attack using large RSA keys |
| CVE-2023-6563 | 7.7 | 68.1 | — | Keycloak: offline session token dos |
| CVE-2026-33871 | 8.7 | 67.1 | — | Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass |
| CVE-2026-57099 | 7.5 | 67.1 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-45646 | 7.5 | 66.4 | — | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-47302 | 7.5 | 66.4 | — | .NET Denial of Service Vulnerability |
| CVE-2026-49787 | 7.5 | 66.4 | — | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-49788 | 7.5 | 66.4 | — | HTTP/2 Denial of Service Vulnerability |
| CVE-2026-50506 | 7.5 | 66.4 | — | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 55 |
| red hat | 36 |
| linux | 20 |
| ibm | 18 |
| elastic | 17 |
| spring | 17 |
| microsoft | 15 |
| netty | 14 |
| rabbitmq | 13 |
| legion of the bouncy castle | 11 |
| erlang | 10 |
| datadog | 9 |
| vllm-project | 9 |
| elixir-mint | 8 |
| gitlab | 8 |