Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-843 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 133 | 122 | 3 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▆█▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 4 · 2026-05 14 · 2026-06 34 · 2026-07 44 · 2026-08 23
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2012-0507 | 9.8 | 99.9 | KEV | Oracle Java SE |
| CVE-2019-0752 | 7.5 | 99.6 | KEV | Microsoft Internet Explorer |
| CVE-2026-21519 | 7.8 | 82.9 | KEV | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2024-21357 | 8.1 | 97.9 | — | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
| CVE-2026-20860 | 7.8 | 94.5 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2021-38658 | 7.8 | 93.0 | — | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2026-40364 | 8.4 | 90.6 | — | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-5946 | 7.5 | 77.7 | — | Invalid handling of CLASS != IN |
| CVE-2026-58289 | 8.3 | 76.3 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57108 | 7.5 | 63.2 | — | .NET Denial of Service Vulnerability |
| CVE-2026-66321 | 9.6 | 62.1 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-29791 | 7.8 | 61.2 | — | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2024-43596 | 6.5 | 58.6 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-54116 | 6.5 | 58.6 | — | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2025-25000 | 8.8 | 58.0 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-59940 | 9.8 | 54.2 | — | Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controll… |
| CVE-2026-28983 | 7.5 | 54.0 | — | — |
| CVE-2024-21363 | 7.8 | 53.8 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-10702 | 4.3 | 51.1 | — | JIT miscompilation in the JavaScript Engine: JIT component |
| CVE-2024-43489 | 8.8 | 51.0 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 45 |
| 31 | |
| mozilla | 9 |
| apple | 6 |
| linux | 4 |
| apache | 2 |
| cedar-policy | 2 |
| mongodb | 2 |
| red hat | 2 |
| the document foundation | 2 |
| @babel | 1 |
| api-platform | 1 |
| azeotech | 1 |
| babel | 1 |
| bps | 1 |