Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-266
Weakness type CWE-266 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 367 | 360 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▃█▅▇▇▁
2025-11 2 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 23 · 2026-06 101 · 2026-07 51 · 2026-08 93 · 2026-09 81 · 2026-10 6
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48172 | 10.0 | 61.9 | KEV | LiteSpeed cPanel Plugin |
| CVE-2025-41115 | 10.0 | 97.0 | — | Incorrect privilege assignment |
| CVE-2025-34112 | 10.0 | 86.3 | — | Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE |
| CVE-2026-49060 | 9.8 | 75.4 | — | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vuln… |
| CVE-2026-15270 | 6.8 | 56.8 | — | D-link DIR-823G Web boa.conf least privilege violation |
| CVE-2026-44173 | 5.3 | 56.5 | — | MariaDB: FILE privilege was not checked for subqueries in the FROM clause |
| CVE-2026-9397 | 8.2 | 53.9 | — | Besen BS20 EV Charging Station OTA Update Installation improper authorization |
| CVE-2026-86153 | 9.4 | 52.1 | — | Tenda CP3 Redirect.cpp SetRedirectEnable privileges management |
| CVE-2026-59093 | 8.7 | 51.9 | — | Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment |
| CVE-2026-15271 | 7.7 | 51.7 | — | TOTOLINK EX200 Web boa.conf least privilege violation |
| CVE-2026-15218 | 7.9 | 51.4 | — | Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts… |
| CVE-2026-86830 | 8.6 | 51.1 | — | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS I… |
| CVE-2026-78330 | 9.8 | 49.0 | — | Apache Syncope: Privilege escalation for admin user via JWT authentication |
| CVE-2026-10059 | 9.1 | 48.8 | — | Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to… |
| CVE-2026-86804 | 6.9 | 48.7 | — | seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization |
| CVE-2025-53744 | 6.8 | 48.6 | — | — |
| CVE-2026-14792 | 6.9 | 48.3 | — | Formbricks Survey actions.ts access control |
| CVE-2026-15467 | 8.1 | 46.7 | — | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypa… |
| CVE-2026-93961 | 6.9 | 45.7 | — | Dromara UJCMS UserController UserController.java usernameExist improper authorization |
| CVE-2026-72839 | 9.3 | 45.5 | — | filebrowser through 2.63.16 Privilege Escalation via Signup |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| sourcecodester | 18 |
| red hat | 15 |
| eleveo | 11 |
| d-link | 6 |
| cosmicstack-labs | 4 |
| nextlevelbuilder | 4 |
| talelin | 4 |
| theonedev | 4 |
| totolink | 4 |
| aomei | 3 |
| berriai | 3 |
| cozy vision technologies pvt | 3 |
| iobit | 3 |
| jetbrains | 3 |
| nanocoai | 3 |