Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-209
Weakness type CWE-209 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 92 | 88 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▄▅▆█▂
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 9 · 2026-06 10 · 2026-07 16 · 2026-08 19 · 2026-09 27 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-29059 | 7.5 | 99.9 | KEV | .NET Framework Information Disclosure Vulnerability |
| CVE-2025-47813 | 4.3 | 99.2 | KEV | Wing FTP Server Wing FTP Server |
| CVE-2013-7331 | 6.5 | 98.9 | KEV | Microsoft Internet Explorer |
| CVE-2026-29146 | 7.5 | 86.4 | — | Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default |
| CVE-2026-67383 | 6.5 | 61.4 | — | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-66306 | 6.5 | 59.0 | — | Skype for Business Information Disclosure Vulnerability |
| CVE-2026-69552 | 5.7 | 58.1 | — | Windows Print Spooler Components Information Disclosure Vulnerability |
| CVE-2018-10624 | 4.3 | 57.6 | — | Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Inf… |
| CVE-2026-20838 | 5.5 | 50.1 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-9794 | 5.3 | 45.5 | — | Keycloak: keycloak: information disclosure via saml ecp endpoint |
| CVE-2026-49365 | 5.3 | 45.5 | — | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, s… |
| CVE-2026-56139 | 5.3 | 45.5 | — | Apache Camel Undertow: The muteException consumer option defaulted to false, so a proce… |
| CVE-2026-66008 | 6.3 | 44.6 | — | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
| CVE-2026-77950 | 6.3 | 43.9 | — | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82733 | 6.3 | 43.9 | — | Route handler return value echoed into AshTypescript error response |
| CVE-2026-78693 | 6.9 | 42.4 | — | Incomplete redaction re-attaches the original error path in AshGraphql, leaking interna… |
| CVE-2026-53906 | 5.1 | 42.1 | — | Path Disclosure and Path Traversal in MCO |
| CVE-2026-47248 | 6.9 | 41.1 | — | Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthen… |
| CVE-2026-43630 | 6.3 | 40.5 | — | llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure |
| CVE-2026-45723 | 2.7 | 40.2 | — | Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in … |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 9 |
| microsoft | 8 |
| ash-project | 7 |
| hcl software | 7 |
| red hat | 5 |
| hclsoftware | 4 |
| parse-community | 4 |
| spring | 4 |
| apache | 3 |
| givanz | 2 |
| hcl | 2 |
| appsmithorg | 1 |
| capgo | 1 |
| codriapp innovation and software technologies | 1 |
| combodo | 1 |