Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-823
Weakness type CWE-823 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 14 | 1 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▅▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▃▁▃█▅▆▆▁
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 4 · 2026-07 2 · 2026-08 3 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-33106 | 8.4 | 53.3 | KEV | Use of Out-of-range Pointer Offset in Graphics |
| CVE-2017-20211 | 8.6 | 53.0 | — | UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE |
| CVE-2026-32829 | 8.2 | 51.2 | — | lz4_flex: Decompression can leak information from uninitialized memory or reused output… |
| CVE-2026-72642 | 8.8 | 47.0 | — | Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inferen… |
| CVE-2026-48977 | 7.7 | 39.0 | — | OpenSlide: Arbitrary memory write with crafted Ventana BIF file |
| CVE-2026-46244 | 9.1 | 37.4 | — | netfilter: nft_inner: Fix IPv6 inner_thoff desync |
| CVE-2026-12290 | 8.1 | 31.6 | — | Memory safety bug fixed in Firefox 152 |
| CVE-2024-42386 | 7.5 | 29.5 | — | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2024-42391 | 5.3 | 18.9 | — | Use of Out-of-range Pointer Offset in Mongoose Web Server library |
| CVE-2026-34193 | 4.3 | 12.1 | — | GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_… |
| CVE-2026-28764 | 7.8 | 11.8 | — | — |
| CVE-2026-45199 | 7.8 | 4.8 | — | GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers |
| CVE-2026-49744 | 7.8 | 4.7 | — | GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() |
| CVE-2026-49745 | 7.8 | 4.7 | — | GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 |
| CVE-2026-21734 | 7.7 | 4.7 | — | GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation |
| CVE-2026-49746 | 7.1 | 3.8 | — | GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem |
| CVE-2026-31912 | 5.5 | 1.0 | — | OOBR in libpcap before 1.10.7 |
| CVE-2026-102757 | 8.5 | 0.9 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| imagination technologies | 6 |
| cesanta | 2 |
| eclipse foundation | 1 |
| elastic | 1 |
| linux | 1 |
| mediaarea | 1 |
| mozilla | 1 |
| openslide | 1 |
| pseitz | 1 |
| qualcomm | 1 |
| the tcpdump group | 1 |
| ucancode.net software | 1 |