Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-824 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 7 | 0 |
▃▁▁▁▃▃▆▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▃▁▃█▆▁
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 3 · 2026-07 2 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-2100 | 7.5 | 64.6 | — | P11-kit: null dereference via c_derivekey with specific null parameters |
| CVE-2026-42959 | 8.7 | 53.1 | — | Crash during DNSSEC validation of malicious content |
| CVE-2026-16353 | 9.8 | 33.9 | — | Invalid pointer in the DOM: Bindings (WebIDL) component |
| CVE-2026-16409 | 7.5 | 21.4 | — | Invalid pointer in the Security: PSM component |
| CVE-2024-46844 | 7.8 | 17.5 | — | um: line: always fill *error_out in setup_one_line() |
| CVE-2024-26799 | 7.0 | 15.2 | — | ASoC: qcom: Fix uninitialized pointer dmactl |
| CVE-2024-50088 | 7.8 | 12.1 | — | btrfs: fix uninitialized pointer free in add_inode_ref() |
| CVE-2024-50087 | 5.5 | 12.1 | — | btrfs: fix uninitialized pointer free on read_alloc_one_name() error |
| CVE-2024-42275 | 5.5 | 10.6 | — | drm/client: Fix error code in drm_client_buffer_vmap_local() |
| CVE-2026-47908 | 7.8 | 5.8 | — | Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824) |
| CVE-2025-39729 | 5.5 | 4.1 | — | crypto: ccp - Fix dereferencing uninitialized error pointer |
| CVE-2026-53042 | 5.5 | 2.3 | — | fwctl: Fix class init ordering to avoid NULL pointer dereference on device removal |
| CVE-2026-47320 | 6.1 | 1.1 | — | — |
| Vendor | CVEs |
|---|---|
| linux | 7 |
| mozilla | 2 |
| adobe | 1 |
| nlnet labs | 1 |
| p11-glue | 1 |
| red hat | 1 |
| samsung open source | 1 |