Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-187
Weakness type CWE-187 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
▃▅▃▃█▁
2026-05 1 · 2026-06 2 · 2026-07 1 · 2026-08 1 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-84376 | 6.3 | 51.8 | — | Astro: Authorization bypass from missing path-segment boundary check when stripping the… |
| CVE-2026-62750 | 6.5 | 50.6 | — | Windows HTTP Protocol Stack Tampering Vulnerability |
| CVE-2026-14687 | 5.5 | 42.7 | — | 666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_result… |
| CVE-2026-87853 | 7.5 | 39.0 | — | Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation |
| CVE-2026-55602 | 6.9 | 29.4 | — | http-proxy-middleware `router` host+path substring matching allows Host-header-driven b… |
| CVE-2026-44837 | 7.5 | 28.2 | — | view_component: System Test Entry Point Path Check Allows Sibling Directory Escape |
| CVE-2026-101914 | 6.5 | 15.0 | — | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for… |
| CVE-2026-45692 | 3.8 | 13.9 | — | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization |
| CVE-2026-81479 | 5.5 | 5.6 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 666ghj | 1 |
| caddyserver | 1 |
| chimurai | 1 |
| dell | 1 |
| grpc | 1 |
| microsoft | 1 |
| red hat | 1 |
| viewcomponent | 1 |
| withastro | 1 |