Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1220
Weakness type CWE-1220 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 33 | 31 | 3 |
Monthly trend
▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▄▂█▄▅▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 2 · 2026-07 11 · 2026-08 5 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-31201 | 9.8 | 96.4 | KEV | Apple Multiple Products |
| CVE-2026-33825 | 7.8 | 31.8 | KEV | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-56155 | 7.8 | 25.9 | KEV | Active Directory Federation Services Elevation of Privilege Vulnerability |
| CVE-2026-39363 | 8.2 | 84.9 | — | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket |
| CVE-2024-43604 | 5.7 | 66.0 | — | Outlook for Android Elevation of Privilege Vulnerability |
| CVE-2026-40365 | 8.8 | 63.1 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-66814 | 8.8 | 54.3 | — | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-77480 | 8.8 | 54.3 | — | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-50502 | 8.8 | 49.6 | — | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-68868 | 6.5 | 46.6 | — | Apache Airflow Google provider: google Secret Manager backend: team scope is never appl… |
| CVE-2026-2651 | 9.0 | 43.2 | — | Missing Authorization Validation in mlflow/mlflow |
| CVE-2026-9088 | 2.7 | 36.9 | — | Keycloak: keycloak: information disclosure due to user profile permission bypass |
| CVE-2026-78216 | 6.0 | 34.8 | — | AshLua eval read operations can read field-policy-protected fields via aggregates |
| CVE-2026-78230 | 6.0 | 34.8 | — | AshAi aggregate tool can read field-policy-protected fields |
| CVE-2026-86338 | 6.0 | 34.8 | — | Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an… |
| CVE-2026-16106 | 4.9 | 34.4 | — | Keycloak-services: keycloak-services: incorrect authorization in admin role-composite d… |
| CVE-2026-16560 | 5.3 | 31.5 | — | 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn |
| CVE-2026-14615 | 2.7 | 29.4 | — | Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child … |
| CVE-2026-14613 | 4.9 | 29.1 | — | Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses … |
| CVE-2026-16108 | 6.5 | 28.6 | — | Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups … |