Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-184
Weakness type CWE-184 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 105 | 102 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▅▆█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 7 · 2026-06 22 · 2026-07 17 · 2026-08 22 · 2026-09 32 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-5217 | 9.2 | 99.9 | KEV | Incomplete Input Validation in GlideExpression Script |
| CVE-2026-49869 | 10.0 | 81.0 | KEV | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authenticat… |
| CVE-2024-30103 | 8.8 | 88.6 | — | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-63108 | 7.7 | 77.3 | — | Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing |
| CVE-2026-87911 | 9.0 | 76.9 | — | Read-only enforcement bypass enabling operating system command execution in the SQL val… |
| CVE-2026-54513 | 8.1 | 67.8 | — | jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allo… |
| CVE-2026-56315 | 9.3 | 65.7 | — | picklescan - Remote Code Execution via Unblocked Standard Library Modules |
| CVE-2026-54512 | 8.1 | 61.5 | — | jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows ar… |
| CVE-2025-71323 | 9.3 | 61.2 | — | picklescan - Remote Code Execution via Unblocked ctypes Module |
| CVE-2026-70470 | 9.5 | 60.7 | — | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE |
| CVE-2026-41934 | 8.7 | 60.0 | — | Vvveb < 1.0.8.2 Authenticated RCE via Code Editor |
| CVE-2026-84218 | 8.1 | 59.9 | — | Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of … |
| CVE-2026-47392 | 9.9 | 57.8 | — | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `ex… |
| CVE-2026-65083 | 9.9 | 57.1 | — | — |
| CVE-2025-71320 | 9.3 | 55.8 | — | picklescan - Remote Code Execution via Incomplete Disallowed Inputs |
| CVE-2026-53836 | 8.7 | 55.8 | — | OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases |
| CVE-2025-29822 | 7.8 | 55.8 | — | Microsoft OneNote Security Feature Bypass Vulnerability |
| CVE-2026-34430 | 8.6 | 55.2 | — | ByteDance DeerFlow LocalSandboxProvider Host Bash Escape |
| CVE-2026-17630 | 8.8 | 53.6 | — | Langflow is affected by security vulnerabilities in Model Context Protocol features |
| CVE-2026-48557 | 8.7 | 53.4 | — | Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| openclaw | 13 |
| picklescan | 6 |
| microsoft | 4 |
| red hat | 4 |
| flowiseai | 3 |
| ibm | 3 |
| symfony | 3 |
| aws | 2 |
| fasterxml | 2 |
| flavorjones | 2 |
| mervinpraison | 2 |
| roocodeinc | 2 |
| steveukx | 2 |
| svg | 2 |
| zed-industries | 2 |