Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-183
Weakness type CWE-183 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 20 | 0 |
Monthly trend
▂▁█▆▄▄▂
2026-04 1 · 2026-05 0 · 2026-06 7 · 2026-07 5 · 2026-08 3 · 2026-09 3 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-3490 | 10.0 | 58.6 | — | picklescan - Universal Blocklist Bypass via pkgutil.resolve_name |
| CVE-2026-42043 | 10.0 | 45.7 | — | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo… |
| CVE-2026-67345 | 8.5 | 45.0 | — | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft |
| CVE-2026-46391 | 8.7 | 43.8 | — | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis |
| CVE-2026-103687 | 5.5 | 43.4 | — | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist |
| CVE-2026-54316 | 6.0 | 42.2 | — | Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch |
| CVE-2026-50189 | 8.9 | 40.2 | — | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route |
| CVE-2026-15625 | 2.1 | 39.1 | — | nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete bl… |
| CVE-2026-54694 | 9.6 | 38.7 | — | NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Adm… |
| CVE-2026-67315 | 6.9 | 37.3 | — | axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 |
| CVE-2026-55581 | 8.4 | 37.2 | — | mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable |
| CVE-2026-90808 | 5.3 | 32.8 | — | HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist |
| CVE-2026-46608 | 7.4 | 32.0 | — | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom… |
| CVE-2026-46341 | 6.1 | 24.9 | — | Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching |
| CVE-2026-59802 | 6.3 | 24.0 | — | PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload |
| CVE-2026-66005 | 5.3 | 23.9 | — | Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding |
| CVE-2026-63649 | 4.1 | 23.6 | — | — |
| CVE-2026-12974 | 7.9 | 19.9 | — | Security Policy Bypass in Forcepoint Security Engine (NGFW) |
| CVE-2026-8918 | 7.1 | 18.5 | — | — |
| CVE-2026-11525 | 3.7 | 13.5 | — | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring m… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| axios | 2 |
| anthropics | 1 |
| apify | 1 |
| appsmithorg | 1 |
| asus | 1 |
| dromara | 1 |
| forcepoint | 1 |
| haxtheweb | 1 |
| hkuds | 1 |
| janhq | 1 |
| nationalsecurityagency | 1 |
| nextlevelbuilder | 1 |
| nicolargo | 1 |
| openvpn | 1 |
| passwordpusher | 1 |