Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1287
Weakness type CWE-1287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 39 | 1 |
Monthly trend
▂▁▁▂▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▃▂▃▁▆▇▅▆█▁
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 5 · 2026-08 6 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-4879 | 9.3 | 100.0 | KEV | Jelly Template Injection Vulnerability in ServiceNow UI Macros |
| CVE-2026-25639 | 7.5 | 77.8 | — | Axios affected by Denial of Service via __proto__ Key in mergeConfig |
| CVE-2026-5946 | 7.5 | 76.4 | — | Invalid handling of CLASS != IN |
| CVE-2026-59680 | 8.6 | 74.7 | — | yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attri… |
| CVE-2026-44249 | 8.1 | 69.2 | — | Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking |
| CVE-2026-50524 | 7.5 | 67.9 | — | .NET Framework Denial of Service Vulnerability |
| CVE-2026-4598 | 7.7 | 60.4 | — | — |
| CVE-2026-24307 | 9.3 | 59.0 | — | M365 Copilot Information Disclosure Vulnerability |
| CVE-2023-3904 | 4.3 | 53.7 | — | Improper Validation of Specified Type of Input in GitLab |
| CVE-2026-86287 | 7.5 | 47.3 | — | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths |
| CVE-2026-55124 | 5.5 | 46.6 | — | Microsoft Word Information Disclosure Vulnerability |
| CVE-2023-3906 | 3.5 | 45.0 | — | Improper Validation of Specified Type of Input in GitLab |
| CVE-2026-9521 | 2.9 | 43.4 | — | fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified ty… |
| CVE-2026-9753 | 7.2 | 42.2 | — | Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. |
| CVE-2026-21932 | 7.4 | 41.7 | — | — |
| CVE-2026-18830 | 8.6 | 41.1 | — | Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API |
| CVE-2026-9742 | 8.2 | 41.0 | — | Authenticate command with specific mechanism parameter can trigger server crash |
| CVE-2026-9390 | 9.1 | 41.0 | — | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup |
| CVE-2026-49941 | 7.5 | 40.2 | — | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses |
| CVE-2026-44935 | 9.9 | 40.0 | — | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFr… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| gitlab | 2 |
| mattermost | 2 |
| mongodb | 2 |
| red hat | 2 |
| suse | 2 |
| arista networks | 1 |
| ash-project | 1 |
| aws | 1 |
| axios | 1 |
| axis communications ab | 1 |
| boost | 1 |
| concrete cms | 1 |
| eclipse foundation | 1 |
| fraillt | 1 |