Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-177
Weakness type CWE-177 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 1 |
Monthly trend
▆█▆▁
2026-07 2 · 2026-08 3 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-76504 | 9.8 | 78.1 | KEV | Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability |
| CVE-2026-41041 | 9.1 | 46.9 | — | Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP RES… |
| CVE-2026-59083 | 9.1 | 28.8 | — | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass |
| CVE-2026-15371 | 8.1 | 28.5 | — | Velociraptor Stored XSS in URL column types |
| CVE-2026-96748 | 8.3 | 15.9 | — | Connection redirection via percent-encoded delimiter injection in connection string hosts |
| CVE-2026-76172 | 7.5 | 12.9 | — | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| CVE-2026-67448 | 6.5 | 11.6 | — | Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026… |