Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-789 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 82 | 81 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▇█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 9 · 2026-06 14 · 2026-07 26 · 2026-08 31
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-49975 | 7.5 | 97.9 | — | Apache HTTP Server: mod_http2 denial of service |
| CVE-2024-43484 | 7.5 | 86.0 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-53917 | 7.5 | 65.1 | — | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U… |
| CVE-2026-66733 | 8.7 | 56.5 | — | Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache |
| CVE-2026-40378 | 7.5 | 54.3 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-42154 | 7.5 | 54.2 | — | Prometheus: remote read endpoint allows denial of service via crafted snappy payload |
| CVE-2026-43868 | 5.3 | 50.6 | — | Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern |
| CVE-2026-42440 | 7.5 | 46.2 | — | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader |
| CVE-2026-65315 | 8.7 | 44.8 | — | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser |
| CVE-2026-44630 | 7.5 | 44.4 | — | Apache IoTDB: RPC service denial of service via unchecked Thrift string length |
| CVE-2026-50734 | 7.5 | 43.3 | — | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWi… |
| CVE-2026-53916 | 7.5 | 43.3 | — | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in… |
| CVE-2026-59844 | 6.5 | 42.3 | — | Libssh: libssh: denial of service via oversized sftp read length |
| CVE-2026-61485 | 7.5 | 42.1 | — | Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index |
| CVE-2026-15337 | 6.9 | 42.1 | — | Potential denial-of-service vulnerability in check_for_language() |
| CVE-2026-67551 | 7.5 | 40.4 | — | Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pr… |
| CVE-2026-67589 | 7.5 | 40.4 | — | Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-aut… |
| CVE-2026-9538 | 7.5 | 37.5 | — | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker control… |
| CVE-2026-75935 | 8.7 | 36.9 | — | Memory-amplification denial of service via declared-length preallocation in Amazon ion-… |
| CVE-2026-15567 | 7.5 | 36.5 | — | Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop … |
| Vendor | CVEs |
|---|---|
| apache | 12 |
| legion of the bouncy castle | 6 |
| elastic | 5 |
| python-pillow | 5 |
| red hat | 3 |
| h2o | 2 |
| m2team | 2 |
| microsoft | 2 |
| open-telemetry | 2 |
| open62541 project / o6 automation | 2 |
| aizuda | 1 |
| allinurl | 1 |
| amazon ion | 1 |
| anthropics | 1 |
| aquasecurity | 1 |