Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-924
Weakness type CWE-924 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
▃▃██▃▁
2026-05 1 · 2026-06 1 · 2026-07 3 · 2026-08 3 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-39827 | 6.5 | 18.8 | — | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh |
| CVE-2026-12576 | 7.5 | 12.2 | — | DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communicati… |
| CVE-2026-48106 | 8.3 | 11.9 | — | Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, e… |
| CVE-2026-13584 | 7.1 | 8.0 | — | Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN commu… |
| CVE-2026-68554 | 2.3 | 7.7 | — | Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attacker… |
| CVE-2026-85104 | 5.3 | 4.5 | — | Brain stimulation parameters can be modified via Bluetooth in Sooma |
| CVE-2026-54891 | 6.3 | 2.5 | — | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client applicatio… |
| CVE-2019-25719 | 8.8 | 2.4 | — | Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling |
| CVE-2026-14681 | 4.2 | 0.0 | — | PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| basekick-labs | 1 |
| coturn | 1 |
| deltaww | 1 |
| dräger | 1 |
| erlang | 1 |
| golang.org/x/crypto | 1 |
| mitsubishi electric | 1 |
| sooma | 1 |