Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-23
Weakness type CWE-23 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 128 | 119 | 4 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█▆▇▁
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 14 · 2026-06 16 · 2026-07 34 · 2026-08 24 · 2026-09 29 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-27199 | 7.3 | 100.0 | KEV | JetBrains TeamCity |
| CVE-2020-5410 | 7.5 | 99.9 | KEV | Directory Traversal with spring-cloud-config-server |
| CVE-2025-64446 | 9.4 | 99.8 | KEV | Fortinet FortiWeb |
| CVE-2026-34926 | 6.7 | 43.3 | KEV | Trend Micro Apex One |
| CVE-2024-43454 | 7.1 | 97.6 | — | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| CVE-2026-23734 | 9.3 | 97.3 | — | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when us… |
| CVE-2023-35359 | 7.8 | 95.4 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-38258 | 7.5 | 91.5 | — | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
| CVE-2023-38185 | 8.8 | 85.3 | — | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-54066 | 7.5 | 83.4 | — | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary… |
| CVE-2026-16053 | 8.5 | 77.3 | — | Path Traversal |
| CVE-2026-51026 | 6.5 | 68.4 | — | — |
| CVE-2026-62837 | 6.5 | 67.9 | — | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-14903 | 6.5 | 66.7 | — | — |
| CVE-2023-40772 | 4.3 | 65.6 | — | — |
| CVE-2026-8134 | 9.4 | 64.8 | — | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp… |
| CVE-2026-52813 | 10.0 | 64.7 | — | Gogs: Path Traversal in organization name results in RCE through Git hooks |
| CVE-2026-67367 | 9.2 | 64.7 | — | — |
| CVE-2026-56196 | 8.8 | 62.3 | — | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-63509 | 8.8 | 62.3 | — | Microsoft Fabric Elevation of Privilege Vulnerability |