Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-200
Weakness type CWE-200 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1382 | 1321 | 18 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▇▇█▁
2025-11 4 · 2025-12 2 · 2026-01 10 · 2026-02 5 · 2026-03 2 · 2026-04 12 · 2026-05 42 · 2026-06 170 · 2026-07 350 · 2026-08 311 · 2026-09 394 · 2026-10 25
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-24919 | 8.6 | 100.0 | KEV | Information disclosure |
| CVE-2021-41277 | 10.0 | 99.9 | KEV | GeoJSON URL validation can expose server files and environment variables to unauthorize… |
| CVE-2016-6415 | 7.5 | 99.8 | KEV | Cisco IOS, IOS XR, and IOS XE |
| CVE-2023-28432 | 7.5 | 99.7 | KEV | Minio Information Disclosure in Cluster Deployment |
| CVE-2023-49103 | 10.0 | 99.6 | KEV | ownCloud ownCloud graphapi |
| CVE-2020-3259 | 7.5 | 99.4 | KEV | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Se… |
| CVE-2025-31125 | 5.3 | 99.2 | KEV | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query |
| CVE-2016-2388 | 5.3 | 98.9 | KEV | SAP NetWeaver |
| CVE-2018-5430 | 7.7 | 98.8 | KEV | TIBCO JasperReports Server Information Disclosure Vulnerability |
| CVE-2008-0655 | 8.8 | 98.5 | KEV | Adobe Acrobat and Reader |
| CVE-2026-20133 | 6.5 | 98.3 | KEV | Cisco Catalyst SD-WAN Manager |
| CVE-2025-68686 | 5.9 | 98.1 | KEV | Fortinet FortiOS |
| CVE-2015-5317 | 7.5 | 97.7 | KEV | Jenkins Jenkins User Interface (UI) |
| CVE-2015-0310 | 7.8 | 96.6 | KEV | Adobe Flash Player |
| CVE-2022-20821 | 6.5 | 95.9 | KEV | Cisco IOS XR Software Health Check Open Port Vulnerability |
| CVE-2026-20805 | 5.5 | 94.1 | KEV | Desktop Window Manager Information Disclosure Vulnerability |
| CVE-2021-25369 | 6.2 | 63.9 | KEV | Samsung Mobile Devices |
| CVE-2023-21237 | 6.2 | 16.8 | KEV | Android Pixel |
| CVE-2024-21626 | 8.6 | 97.2 | — | runc container breakout through process.cwd trickery and leaked fds |
| CVE-2026-32315 | 5.5 | 86.7 | — | motionEye: World-Readable Configuration File Exposes Admin Password Hash |