Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1025
Weakness type CWE-1025 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 12 | 12 | 0 |
Monthly trend
▃▂▃█▂
2026-06 2 · 2026-07 1 · 2026-08 2 · 2026-09 6 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-71377 | 8.7 | 50.3 | — | stoatchat before 20250210-1 Unrestricted Message History Fetch |
| CVE-2026-9800 | 8.1 | 49.6 | — | Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect … |
| CVE-2026-78619 | 9.8 | 48.1 | — | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code… |
| CVE-2026-75840 | 8.7 | 35.5 | — | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex |
| CVE-2026-93854 | 7.2 | 32.7 | — | — |
| CVE-2026-100248 | 8.4 | 32.7 | — | — |
| CVE-2026-14441 | 6.9 | 27.1 | — | Logic flaw in SANnav Java cache key handling object comparison handling |
| CVE-2023-54390 | 8.7 | 25.2 | — | PocketMine-MP before 5.3.1 Denial of Service via LoginPacket |
| CVE-2026-29811 | 7.7 | 24.9 | — | — |
| CVE-2026-79677 | 7.5 | 23.2 | — | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout |
| CVE-2026-104048 | 6.8 | 18.4 | — | Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation |
| CVE-2026-48860 | 7.5 | 10.3 | — | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusio… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 2 |
| apache | 1 |
| arcadedata | 1 |
| brocade | 1 |
| cyberpanel | 1 |
| erlang | 1 |
| openstack | 1 |
| pmmp | 1 |
| rattadan | 1 |
| stoatchat | 1 |