Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-772 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 28 | 26 | 1 |
▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▃█▆▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 7 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-20481 | 5.8 | 96.6 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2024-1300 | 5.4 | 62.0 | — | Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support |
| CVE-2026-48006 | 8.7 | 51.8 | — | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| CVE-2026-39830 | 9.1 | 47.1 | — | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypt… |
| CVE-2026-48043 | 7.5 | 46.9 | — | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener … |
| CVE-2026-36590 | 7.5 | 33.5 | — | — |
| CVE-2026-64607 | 5.3 | 29.1 | — | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to… |
| CVE-2026-15713 | 5.9 | 28.1 | — | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service vi… |
| CVE-2026-20124 | 7.7 | 27.7 | — | Cisco IOS XE Software SNMP Denial of Service Vulnerability |
| CVE-2026-61387 | 6.9 | 27.6 | — | — |
| CVE-2026-73508 | 5.3 | 26.3 | — | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| CVE-2026-73215 | 7.1 | 26.1 | — | The coturn server can end in a state where it does not accept more requests with "even-… |
| CVE-2026-13351 | 7.5 | 25.3 | — | net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incomi… |
| CVE-2026-40209 | 5.3 | 21.6 | — | Denial of service via IXFR queries |
| CVE-2026-41637 | 3.7 | 18.6 | — | Degradation of resolution service from improperly accounted client-terminated DNS-over-… |
| CVE-2026-49343 | 5.9 | 18.4 | — | Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / s… |
| CVE-2026-12353 | 5.3 | 17.7 | — | Rhcs: memory leak during https connection leads to denial of service |
| CVE-2026-13505 | 8.7 | 17.0 | — | Zeroisation of sensitive key material on garbage collection relies on finalization |
| CVE-2026-11811 | 3.7 | 17.0 | — | Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to reso… |
| CVE-2026-56444 | 5.9 | 15.0 | — | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-time… |
| Vendor | CVEs |
|---|---|
| linux | 4 |
| netty | 4 |
| red hat | 3 |
| cisco | 2 |
| nlnet labs | 2 |
| apache | 1 |
| bytecodealliance | 1 |
| coturn | 1 |
| eclipse foundation | 1 |
| golang.org/x/crypto | 1 |
| klever-io | 1 |
| legion of the bouncy castle | 1 |
| open-telemetry | 1 |
| powerdns | 1 |
| tanium | 1 |