Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-27
Weakness type CWE-27 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 4 | 1 |
Monthly trend
█▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁███▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 1 · 2026-08 1 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-23897 | 9.8 | 100.0 | KEV | Jenkins Jenkins Command Line Interface (CLI) |
| CVE-2026-62391 | 8.1 | 54.7 | — | Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-con… |
| CVE-2026-24457 | 9.8 | 48.8 | — | — |
| CVE-2026-76344 | 7.7 | 32.9 | — | Path Traversal through the Search Dispatch REST API in Splunk Enterprise |
| CVE-2026-17495 | 5.9 | 27.1 | — | moment vulnerable to Path Traversal via crafted non-string locale name |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 1 |
| eclipse foundation | 1 |
| jenkins project | 1 |
| moment | 1 |
| splunk | 1 |