Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-772
Weakness type CWE-772 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 47 | 45 | 1 |
Monthly trend
▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▆▅▆█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 7 · 2026-08 10 · 2026-09 13 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-20481 | 5.8 | 96.8 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2026-3104 | 7.5 | 66.4 | — | Memory leak in code preparing DNSSEC proofs of non-existence |
| CVE-2024-1300 | 5.4 | 63.5 | — | Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support |
| CVE-2026-69664 | 8.7 | 59.9 | — | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
| CVE-2026-48043 | 7.5 | 57.7 | — | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener … |
| CVE-2026-48006 | 8.7 | 56.7 | — | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| CVE-2026-40209 | 5.3 | 51.5 | — | Denial of service via IXFR queries |
| CVE-2026-71380 | 8.7 | 50.4 | — | httpd applies no timeout while receiving a request body, parking a worker on a stalled … |
| CVE-2026-92983 | 8.7 | 49.7 | — | InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch |
| CVE-2026-63128 | 7.5 | 48.4 | — | RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server trans… |
| CVE-2026-39830 | 9.1 | 48.0 | — | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypt… |
| CVE-2026-61387 | 6.9 | 47.9 | — | — |
| CVE-2026-77384 | 7.5 | 47.3 | — | libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows re… |
| CVE-2026-59654 | 6.8 | 46.4 | — | Apache CloudStack: DoS caused by database connections leak |
| CVE-2026-36590 | 7.5 | 46.2 | — | — |
| CVE-2026-20250 | 8.6 | 44.0 | — | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense So… |
| CVE-2026-85718 | 5.9 | 43.0 | — | AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial… |
| CVE-2026-94625 | 6.9 | 42.2 | — | vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders |
| CVE-2026-20124 | 7.7 | 40.8 | — | Cisco IOS XE Software SNMP Denial of Service Vulnerability |
| CVE-2026-92230 | 7.5 | 39.8 | — | Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 6 |
| linux | 5 |
| netty | 4 |
| cisco | 3 |
| red hat | 3 |
| erlang | 2 |
| nlnet labs | 2 |
| asynchttpclient | 1 |
| bytecodealliance | 1 |
| coturn | 1 |
| eclipse foundation | 1 |
| golang.org/x/crypto | 1 |
| internlm | 1 |
| isc | 1 |
| klever-io | 1 |