Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-825 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 39 | 37 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▄█▂▁
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 21 · 2026-07 4 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45447 | 8.8 | 91.9 | — | Heap Use-After-Free in the PKCS7_verify() Function |
| CVE-2026-3593 | 9.8 | 72.9 | — | Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation |
| CVE-2026-6722 | 9.5 | 56.7 | — | Use-After-Free in SOAP using Apache map |
| CVE-2025-49794 | 9.1 | 51.5 | — | Libxml: heap use after free (uaf) leads to denial of service (dos) |
| CVE-2026-6100 | 9.1 | 45.1 | — | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after r… |
| CVE-2026-12328 | 8.1 | 39.3 | — | Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140… |
| CVE-2026-44422 | 8.8 | 36.1 | — | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion |
| CVE-2026-53006 | 9.8 | 32.9 | — | ipv6: fix possible UAF in icmpv6_rcv() |
| CVE-2026-12291 | 8.8 | 31.5 | — | Use-after-free in the Networking: HTTP component |
| CVE-2026-46243 | 7.1 | 31.0 | — | smb: client: reject userspace cifs.spnego descriptions |
| CVE-2026-57435 | 1.7 | 30.0 | — | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::A… |
| CVE-2026-12326 | 8.1 | 29.5 | — | Memory safety bugs fixed in Firefox 152 and Thunderbird 152 |
| CVE-2026-8854 | 7.5 | 29.2 | — | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-45972 | 9.8 | 26.3 | — | smb: client: fix potential UAF and double free in smb2_open_file() |
| CVE-2026-52924 | 9.8 | 26.1 | — | sctp: purge outqueue on stale COOKIE-ECHO handling |
| CVE-2026-53175 | 9.8 | 24.1 | — | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-58592 | 8.9 | 23.9 | — | Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssem… |
| CVE-2026-12293 | 9.8 | 22.9 | — | Use-after-free in the Graphics: WebGPU component |
| CVE-2026-46125 | 8.8 | 22.9 | — | wifi: mac80211: remove station if connection prep fails |
| CVE-2026-46523 | 6.2 | 22.8 | — | ImageMagick: Use-After-Free in MSL decoder. |
| Vendor | CVEs |
|---|---|
| linux | 18 |
| red hat | 5 |
| mozilla | 4 |
| corewcf | 1 |
| freerdp | 1 |
| ibm | 1 |
| imagemagick | 1 |
| isc | 1 |
| ladybirdbrowser | 1 |
| openssl | 1 |
| php group | 1 |
| python software foundation | 1 |
| sparklemotion | 1 |
| the document foundation | 1 |
| zephyrproject | 1 |