Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-201
Weakness type CWE-201 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 126 | 126 | 0 |
Monthly trend
▁▁▁▂█▆▆▇▃
2026-02 1 · 2026-03 1 · 2026-04 1 · 2026-05 6 · 2026-06 33 · 2026-07 25 · 2026-08 24 · 2026-09 26 · 2026-10 9
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47717 | 7.5 | 71.1 | — | FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device C… |
| CVE-2026-65812 | 6.8 | 58.1 | — | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2026-54649 | 2.1 | 56.3 | — | punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloud… |
| CVE-2026-44487 | 8.2 | 53.7 | — | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redire… |
| CVE-2026-44486 | 7.5 | 53.7 | — | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated t… |
| CVE-2026-32829 | 8.2 | 51.2 | — | lz4_flex: Decompression can leak information from uninitialized memory or reused output… |
| CVE-2026-63481 | 6.9 | 50.0 | — | Hurl: Cookies in Cookies section leak when redirecting to a different host |
| CVE-2026-8924 | 9.1 | 49.9 | — | trailing dot domain super cookie |
| CVE-2026-4035 | 7.7 | 49.8 | — | Environment Variable Resolution Vulnerability in mlflow/mlflow |
| CVE-2026-55553 | 7.5 | 49.9 | — | urllib: Cross-origin redirects preserve credential-bearing request headers, leading to … |
| CVE-2026-100258 | 4.3 | 49.5 | — | — |
| CVE-2026-6267 | 5.3 | 47.5 | — | Insertion of Sensitive Information Into Sent Data in GitLab |
| CVE-2026-42880 | 9.6 | 44.9 | — | ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction |
| CVE-2026-67425 | 8.6 | 44.4 | — | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url |
| CVE-2026-78374 | 6.9 | 43.3 | — | Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page … |
| CVE-2026-66901 | 7.5 | 42.5 | — | Google::Auth versions before 0.09 for Perl allow server side request forgery and creden… |
| CVE-2026-27868 | 6.9 | 42.4 | — | PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT |
| CVE-2026-86497 | 6.8 | 41.6 | — | — |
| CVE-2026-64643 | 6.3 | 41.4 | — | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints |
| CVE-2026-80255 | 7.5 | 39.1 | — | secure cookie attribute bypass with tab |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| jetbrains | 4 |
| curl | 3 |
| red hat | 3 |
| aws | 2 |
| axios | 2 |
| devolutions | 2 |
| eclipse foundation | 2 |
| gitlab | 2 |
| guzzle | 2 |
| pnpm | 2 |
| tryghost | 2 |
| 10up | 1 |
| acacode | 1 |
| akshay menariya | 1 |
| al monsor | 1 |