Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-825
Weakness type CWE-825 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 48 | 41 | 0 |
Monthly trend
▂▁▁▁▁▂▁▁▁▁▁▄█▂▂▂▁
2025-11 4 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 9 · 2026-06 20 · 2026-07 4 · 2026-08 3 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45447 | 8.8 | 90.2 | — | Heap Use-After-Free in the PKCS7_verify() Function |
| CVE-2026-6722 | 9.5 | 69.3 | — | Use-After-Free in SOAP using Apache map |
| CVE-2025-49794 | 9.1 | 56.2 | — | Libxml: heap use after free (uaf) leads to denial of service (dos) |
| CVE-2026-6100 | 9.1 | 53.7 | — | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after r… |
| CVE-2026-44422 | 8.8 | 49.6 | — | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion |
| CVE-2025-49795 | 7.5 | 46.4 | — | Libxml: null pointer dereference leads to denial of service (dos) |
| CVE-2026-58592 | 8.9 | 44.0 | — | Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssem… |
| CVE-2026-53006 | 9.8 | 42.7 | — | ipv6: fix possible UAF in icmpv6_rcv() |
| CVE-2026-52924 | 9.8 | 42.6 | — | sctp: purge outqueue on stale COOKIE-ECHO handling |
| CVE-2026-12328 | 8.1 | 38.9 | — | Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140… |
| CVE-2026-45972 | 9.8 | 38.2 | — | smb: client: fix potential UAF and double free in smb2_open_file() |
| CVE-2026-8854 | 7.5 | 37.7 | — | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-57435 | 1.7 | 37.7 | — | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::A… |
| CVE-2026-53175 | 9.8 | 36.9 | — | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-46125 | 8.8 | 36.2 | — | wifi: mac80211: remove station if connection prep fails |
| CVE-2026-65970 | 5.3 | 34.5 | — | OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_nativ… |
| CVE-2026-77220 | 7.1 | 34.2 | — | PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting |
| CVE-2026-46523 | 6.2 | 33.7 | — | ImageMagick: Use-After-Free in MSL decoder. |
| CVE-2026-78123 | 5.9 | 33.2 | — | — |
| CVE-2026-12291 | 8.8 | 29.8 | — | Use-after-free in the Networking: HTTP component |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 18 |
| red hat | 10 |
| gnu | 4 |
| mozilla | 4 |
| wireshark foundation | 2 |
| academysoftwarefoundation | 1 |
| corewcf | 1 |
| freerdp | 1 |
| gnome | 1 |
| ibm | 1 |
| imagemagick | 1 |
| ladybirdbrowser | 1 |
| michaelrsweet | 1 |
| openssl | 1 |
| php group | 1 |