Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-212
Weakness type CWE-212 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 22 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▃▄▂█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 2 · 2026-06 3 · 2026-07 4 · 2026-08 1 · 2026-09 10 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40895 | 6.9 | 55.8 | — | follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets |
| CVE-2026-62900 | 5.9 | 53.3 | — | .NET Information Disclosure Vulnerability |
| CVE-2024-43554 | 5.5 | 48.7 | — | Windows Kernel-Mode Driver Information Disclosure Vulnerability |
| CVE-2026-42880 | 9.6 | 44.9 | — | ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction |
| CVE-2026-45737 | 6.5 | 42.2 | — | Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations |
| CVE-2026-54421 | 6.8 | 38.4 | — | — |
| CVE-2026-16104 | 6.5 | 37.3 | — | Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptc… |
| CVE-2026-46657 | 7.1 | 35.8 | — | Bludit's persistent authentication tokens not revoked upon account disablement |
| CVE-2026-20928 | 4.6 | 35.0 | — | Windows Recovery Environment Security Feature Bypass Vulnerability |
| CVE-2026-85094 | 8.8 | 34.8 | — | — |
| CVE-2026-82069 | 5.1 | 32.9 | — | Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization o… |
| CVE-2026-67071 | 6.5 | 29.4 | — | HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Infor… |
| CVE-2026-78658 | 6.5 | 29.4 | — | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclos… |
| CVE-2026-90860 | 7.1 | 21.1 | — | — |
| CVE-2026-86740 | 5.1 | 19.8 | — | Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains |
| CVE-2026-73440 | 2.3 | 17.1 | — | Security Advisory 0178 |
| CVE-2026-96879 | 6.9 | 16.4 | — | "Checked by" label in page history should not be shown if the underlying review log ent… |
| CVE-2026-36178 | 4.6 | 9.8 | — | — |
| CVE-2026-53604 | 7.1 | 7.2 | — | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-45046 | 5.5 | 3.7 | — | Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| argoproj | 2 |
| canva | 2 |
| ibm | 2 |
| red hat | 2 |
| arista networks | 1 |
| bludit | 1 |
| canonical | 1 |
| follow-redirects | 1 |
| forgekeep | 1 |
| grokability | 1 |
| hclsoftware | 1 |
| mongodb | 1 |
| openstack | 1 |
| safedep | 1 |