Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-834 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 6 | 0 |
▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▅█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 1 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-64641 | 8.2 | 46.1 | — | Next.js: Denial of Service in App Router using Server Actions |
| CVE-2026-45680 | 7.5 | 24.7 | — | OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU |
| CVE-2026-59644 | 8.7 | 18.2 | — | MLS hash-ratchet honours arbitrary 32-bit generation counter from sender |
| CVE-2024-42071 | 5.5 | 12.9 | — | ionic: use dev_consume_skb_any outside of napi |
| CVE-2026-50171 | 8.2 | 5.8 | — | Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) |
| CVE-2026-71852 | 4.8 | 2.8 | — | pypdf: Possible long runtimes/large memory usage for large CID font width ranges |
| CVE-2026-48156 | 5.1 | 2.6 | — | pypdf: Possible long runtimes for zero-only width values in cross-reference streams |
| Vendor | CVEs |
|---|---|
| py-pdf | 2 |
| angular | 1 |
| legion of the bouncy castle | 1 |
| linux | 1 |
| open-telemetry | 1 |
| vercel | 1 |