boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-825

Weakness type CWE-825 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
39370

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▄█▂▁

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 21 · 2026-07 4 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-454478.891.9Heap Use-After-Free in the PKCS7_verify() Function
CVE-2026-35939.872.9Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-67229.556.7Use-After-Free in SOAP using Apache map
CVE-2025-497949.151.5Libxml: heap use after free (uaf) leads to denial of service (dos)
CVE-2026-61009.145.1Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after r…
CVE-2026-123288.139.3Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140…
CVE-2026-444228.836.1FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion
CVE-2026-530069.832.9ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-122918.831.5Use-after-free in the Networking: HTTP component
CVE-2026-462437.131.0smb: client: reject userspace cifs.spnego descriptions
CVE-2026-574351.730.0Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::A…
CVE-2026-123268.129.5Memory safety bugs fixed in Firefox 152 and Thunderbird 152
CVE-2026-88547.529.2IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-459729.826.3smb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-529249.826.1sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-531759.824.1inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
CVE-2026-585928.923.9Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssem…
CVE-2026-122939.822.9Use-after-free in the Graphics: WebGPU component
CVE-2026-461258.822.9wifi: mac80211: remove station if connection prep fails
CVE-2026-465236.222.8ImageMagick: Use-After-Free in MSL decoder.

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux18
red hat5
mozilla4
corewcf1
freerdp1
ibm1
imagemagick1
isc1
ladybirdbrowser1
openssl1
php group1
python software foundation1
sparklemotion1
the document foundation1
zephyrproject1