Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-835 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 107 | 93 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅█▃
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 9 · 2026-06 22 · 2026-07 44 · 2026-08 15
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-20353 | 8.6 | 99.3 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2026-4890 | 7.5 | 93.8 | — | CVE-2026-4890 |
| CVE-2026-42899 | 7.5 | 82.9 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-33116 | 7.5 | 80.6 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43512 | 6.5 | 80.4 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
| CVE-2026-46522 | 7.5 | 77.4 | — | ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion |
| CVE-2026-43871 | 8.7 | 62.3 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt… |
| CVE-2026-50647 | 7.5 | 62.3 | — | Active Directory Federation Server Denial of Service Vulnerability |
| CVE-2026-55199 | 8.2 | 57.5 | — | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler |
| CVE-2026-54119 | 7.5 | 54.3 | — | Windows Active Directory Denial of Service Vulnerability |
| CVE-2026-50324 | 5.9 | 53.2 | — | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50653 | 7.5 | 53.1 | — | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-47066 | 8.7 | 52.2 | — | Infinite loop in Alt-Svc header parser in hackney |
| CVE-2024-36288 | 5.5 | 52.1 | — | SUNRPC: Fix loop termination condition in gss_free_in_token_pages() |
| CVE-2025-71319 | 8.7 | 51.4 | — | image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser |
| CVE-2026-59933 | 7.5 | 50.0 | — | PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion |
| CVE-2025-8194 | 7.5 | 46.6 | — | Tarfile infinite loop during parsing with negative member offset |
| CVE-2026-66730 | 8.7 | 45.9 | — | facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser |
| CVE-2026-44186 | 7.3 | 45.3 | — | Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp |
| CVE-2026-11352 | 7.5 | 45.0 | — | QUIC zero-length UDP datagrams busy-loop |
| Vendor | CVEs |
|---|---|
| linux | 22 |
| red hat | 8 |
| microsoft | 7 |
| ibm | 5 |
| zephyrproject | 5 |
| imagemagick | 4 |
| py-pdf | 4 |
| image-size | 3 |
| apache | 2 |
| codechild | 2 |
| mermaid-js | 2 |
| nanoid_project | 2 |
| 101arrowz | 1 |
| @fastify/busboy | 1 |
| benoitc | 1 |