Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-269
Weakness type CWE-269 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1068 | 967 | 22 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▅▄█▁▇▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁
2022-04 0 · 2022-05 0 · 2022-06 0 · 2022-07 0 · 2022-08 0 · 2022-09 0 · 2022-10 0 · 2022-11 0 · 2022-12 0 · 2023-01 0 · 2023-02 1 · 2023-03 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-5689 | 9.8 | 99.8 | KEV | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard… |
| CVE-2021-20021 | 9.8 | 99.8 | KEV | SonicWall SonicWall Email Security |
| CVE-2016-0151 | 7.8 | 99.2 | KEV | Microsoft Client-Server Run-time Subsystem (CSRSS) |
| CVE-2020-8655 | 7.8 | 99.1 | KEV | EyesOfNetwork EyesOfNetwork |
| CVE-2019-1405 | 7.8 | 98.2 | KEV | Microsoft Windows |
| CVE-2019-1215 | 7.8 | 97.3 | KEV | Microsoft Windows |
| CVE-2013-0643 | 8.8 | 95.6 | KEV | Adobe Flash Player |
| CVE-2019-1388 | 7.8 | 94.9 | KEV | Microsoft Windows |
| CVE-2023-28434 | 8.8 | 94.6 | KEV | MinIO is vulnerable to privilege escalation on Linux/MacOS |
| CVE-2020-3950 | 7.8 | 94.2 | KEV | VMware Multiple Products |
| CVE-2024-38014 | 7.8 | 93.4 | KEV | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2002-0367 | 7.8 | 91.9 | KEV | Microsoft Windows |
| CVE-2026-21533 | 7.8 | 90.5 | KEV | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2024-26169 | 7.8 | 90.3 | KEV | Windows Error Reporting Service Elevation of Privilege Vulnerability |
| CVE-2024-8068 | 5.1 | 88.7 | KEV | Privilege escalation to NetworkService Account access |
| CVE-2021-25337 | 4.4 | 86.0 | KEV | Samsung Mobile Devices |
| CVE-2023-35674 | 8.8 | 84.9 | KEV | Android Framework |
| CVE-2024-49035 | 8.7 | 69.5 | KEV | Partner.Microsoft.Com Elevation of Privilege Vulnerability |
| CVE-2021-23874 | 8.2 | 62.4 | KEV | McAfee Total Protection (MTP) privilege escalation vulnerability |
| CVE-2026-84869 | 9.9 | 59.1 | KEV | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| oracle | 368 |
| microsoft | 88 |
| 51 | |
| mozilla | 31 |
| ibm | 29 |
| hewlett packard enterprise (hpe) | 23 |
| red hat | 15 |
| dell | 13 |
| apple | 11 |
| apache | 8 |
| fission | 8 |
| getgrav | 8 |
| mervinpraison | 6 |
| arcadedata | 5 |
| cap-go | 5 |