Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-250
Weakness type CWE-250 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 79 | 68 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▁▁▁▁▂▆▅▆█▁
2025-11 0 · 2025-12 2 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 15 · 2026-07 12 · 2026-08 15 · 2026-09 21 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-38813 | 7.5 | 97.0 | KEV | Privilege escalation vulnerability |
| CVE-2025-40602 | 6.6 | 85.7 | KEV | SonicWall SMA1000 appliance |
| CVE-2024-7387 | 9.1 | 82.7 | — | Openshift/builder: path traversal allows command injection in privileged buildcontainer… |
| CVE-2024-43583 | 7.8 | 70.3 | — | Winlogon Elevation of Privilege Vulnerability |
| CVE-2023-5207 | 8.2 | 68.1 | — | Execution with Unnecessary Privileges in GitLab |
| CVE-2026-54501 | 9.4 | 67.6 | — | Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git UR… |
| CVE-2026-77521 | 10.0 | 63.0 | — | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-69409 | 6.5 | 61.4 | — | Microsoft Office SharePoint Information Disclosure Vulnerability |
| CVE-2026-42833 | 9.1 | 59.3 | — | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-48584 | 8.8 | 58.7 | — | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-59133 | 8.8 | 58.7 | — | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
| CVE-2026-69464 | 8.8 | 58.7 | — | Microsoft Office SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-84787 | 8.1 | 56.6 | — | Privilege Escalation vulnerability |
| CVE-2026-72508 | 9.9 | 55.4 | — | Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ser… |
| CVE-2026-18982 | 8.8 | 54.8 | — | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit… |
| CVE-2026-17110 | 8.8 | 53.2 | — | IBM i is Affected By Multiple Vulnerabilities in SQL |
| CVE-2026-18669 | 8.8 | 53.2 | — | IBM i is Affected By A Privilege Escalation Vulnerability [] |
| CVE-2026-18608 | 8.7 | 51.5 | — | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflo… |
| CVE-2026-92574 | 8.8 | 49.6 | — | Cri-o: cri-o checkpoint restore bypasses destination security context |
| CVE-2026-18949 | 8.8 | 46.9 | — | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac … |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 13 |
| microsoft | 6 |
| ibm | 5 |
| xen | 5 |
| fission | 4 |
| 4 | |
| canonical | 2 |
| dell | 2 |
| 0x5t4l1n | 1 |
| 1panel-dev | 1 |
| acronis | 1 |
| analog way | 1 |
| binsoft | 1 |
| broadcom | 1 |
| cloudnative-pg | 1 |