Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-824
Weakness type CWE-824 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 26 | 18 | 2 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▃▃▅▁▁▁▁▁▁▁▁▁▁▃▁▁▁▅▁▃▃▆▆▅▃█▃
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 3 · 2026-06 3 · 2026-07 2 · 2026-08 1 · 2026-09 4 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-21971 | 7.8 | 99.0 | KEV | Windows Runtime Remote Code Execution Vulnerability |
| CVE-2015-1770 | 8.8 | 98.4 | KEV | Microsoft Office |
| CVE-2026-2100 | 7.5 | 66.0 | — | P11-kit: null dereference via c_derivekey with specific null parameters |
| CVE-2026-67281 | 8.7 | 52.5 | — | Unauthenticated file read in Mikrotik RouterOS |
| CVE-2026-42959 | 8.7 | 52.1 | — | Crash during DNSSEC validation of malicious content |
| CVE-2026-45736 | 7.5 | 50.5 | — | ws: Uninitialized memory disclosure |
| CVE-2026-16353 | 9.8 | 41.9 | — | Invalid pointer in the DOM: Bindings (WebIDL) component |
| CVE-2026-39458 | 8.7 | 37.7 | — | BIG-IP DNS Cache vulnerability |
| CVE-2026-100788 | 9.8 | 36.2 | — | Invalid pointer in the JavaScript: WebAssembly component |
| CVE-2026-66081 | 8.7 | 34.6 | — | Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-version… |
| CVE-2026-54920 | 0.0 | 27.0 | — | OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil… |
| CVE-2026-47908 | 7.8 | 19.9 | — | Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824) |
| CVE-2026-16409 | 7.5 | 19.4 | — | Invalid pointer in the Security: PSM component |
| CVE-2024-46844 | 7.8 | 15.7 | — | um: line: always fill *error_out in setup_one_line() |
| CVE-2026-27300 | 5.5 | 15.7 | — | Adobe Framemaker | Access of Uninitialized Pointer (CWE-824) |
| CVE-2026-21275 | 7.8 | 14.5 | — | InDesign Desktop | Access of Uninitialized Pointer (CWE-824) |
| CVE-2026-21276 | 7.8 | 14.5 | — | InDesign Desktop | Access of Uninitialized Pointer (CWE-824) |
| CVE-2024-26799 | 7.0 | 13.8 | — | ASoC: qcom: Fix uninitialized pointer dmactl |
| CVE-2024-50088 | 7.8 | 10.7 | — | btrfs: fix uninitialized pointer free in add_inode_ref() |
| CVE-2024-50087 | 5.5 | 10.7 | — | btrfs: fix uninitialized pointer free on read_alloc_one_name() error |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 7 |
| adobe | 4 |
| mozilla | 3 |
| academysoftwarefoundation | 1 |
| apache | 1 |
| f5 | 1 |
| microsoft | 1 |
| mikrotik | 1 |
| nlnet labs | 1 |
| nvidia | 1 |
| p11-glue | 1 |
| red hat | 1 |
| samsung open source | 1 |
| tesseract-ocr | 1 |
| websockets | 1 |