Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1188
Weakness type CWE-1188 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 87 | 79 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▆▅█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 7 · 2026-06 19 · 2026-07 16 · 2026-08 11 · 2026-09 21 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-13927 | 9.8 | 100.0 | KEV | Apache Airflow's Experimental API |
| CVE-2023-27524 | 8.9 | 99.9 | KEV | Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
| CVE-2022-24706 | 9.8 | 99.8 | KEV | Remote Code Execution Vulnerability in Packaging |
| CVE-2025-48927 | 5.3 | 95.8 | KEV | TeleMessage TM SGNL |
| CVE-2023-6448 | 9.8 | 80.8 | KEV | Unitronics VisiLogic uses a default administrative password |
| CVE-2026-67208 | 9.3 | 90.8 | — | Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console |
| CVE-2026-47668 | 10.0 | 89.9 | — | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner |
| CVE-2026-44825 | 9.8 | 86.2 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-54066 | 7.5 | 83.4 | — | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary… |
| CVE-2026-66066 | 9.5 | 81.0 | — | Action Pack: Possible arbitrary file read and remote code execution in Active Storage v… |
| CVE-2026-52824 | 9.1 | 70.2 | — | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-87827 | 10.0 | 63.9 | — | KGUARD DVR unauthenticated remote command execution vulnerability |
| CVE-2026-50519 | 7.5 | 59.0 | — | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-57127 | 9.8 | 58.3 | — | praisonai: recipe serve auth middleware silently disables itself when no secret is set |
| CVE-2026-14474 | 8.8 | 55.8 | — | Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by d… |
| CVE-2026-47393 | 9.8 | 54.4 | — | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2025-59321 | 9.8 | 54.2 | — | — |
| CVE-2026-77915 | 9.3 | 54.2 | — | rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php |
| CVE-2026-57147 | 9.8 | 54.1 | — | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token for… |
| CVE-2026-57139 | 9.8 | 53.5 | — | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 7 |
| mervinpraison | 6 |
| linux | 3 |
| siyuan-note | 3 |
| 2 | |
| joomdonation.com | 2 |
| messagepack-csharp | 2 |
| sharp | 2 |
| vps.org | 2 |
| xyproto | 2 |
| alibaba | 1 |
| anjvision | 1 |
| appsmithorg | 1 |
| argoproj | 1 |
| aws | 1 |