Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-15
Weakness type CWE-15 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 21 | 20 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▃▅▄▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 4 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45087 | 10.0 | 71.3 | — | Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode |
| CVE-2026-44417 | 7.5 | 58.4 | — | Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to … |
| CVE-2026-73661 | 8.6 | 46.9 | — | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup |
| CVE-2026-87987 | 10.0 | 44.9 | — | — |
| CVE-2026-46399 | 9.4 | 40.1 | — | Authenticated Remote Code Execution via File Overwrite |
| CVE-2026-46485 | 8.2 | 34.1 | — | Dash: Users can write to config despire permissions (OIDC tested) |
| CVE-2026-54918 | 5.3 | 33.6 | — | NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) … |
| CVE-2019-25716 | 7.1 | 33.4 | — | Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet |
| CVE-2026-13745 | 7.7 | 29.1 | — | Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI… |
| CVE-2026-19593 | 9.8 | 28.1 | — | — |
| CVE-2025-8283 | 3.7 | 22.7 | — | Netavark: podman: netavark may resolve hostnames to unexpected hosts |
| CVE-2026-103442 | 7.2 | 18.5 | — | MergeAccount PHP object injection via session-key substitution |
| CVE-2026-44768 | 4.1 | 16.0 | — | Security misconfiguration in SAP CRM (WebClient UI) |
| CVE-2026-0418 | 4.3 | 14.2 | — | Certain NETGEAR devices allow administrators to tamper with system |
| CVE-2026-16708 | 7.5 | 14.2 | — | IBM Db2 Mirror for i is affected by multiple vulnerabilities |
| CVE-2026-66065 | 8.4 | 13.8 | — | Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing key… |
| CVE-2026-1784 | 8.8 | 8.2 | — | Ose-cluster-ingress-operator: remote code execution through haproxy configuration injec… |
| CVE-2026-19884 | 8.4 | 8.1 | — | — |
| CVE-2026-85217 | 8.6 | 7.5 | — | Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop |
| CVE-2026-56567 | 3.3 | 2.9 | — | HCL iControl is affected by multiple security vulnerabilities. |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| openai | 2 |
| red hat | 2 |
| apache | 1 |
| autodesk | 1 |
| dräger | 1 |
| eclipse foundation | 1 |
| freepbx | 1 |
| google cloud | 1 |
| hahwul | 1 |
| haxtheweb | 1 |
| hcl software | 1 |
| ibm | 1 |
| lissy93 | 1 |
| mistralai | 1 |
| netbox-community | 1 |