Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-276
Weakness type CWE-276 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 82 | 70 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▁▄▇▇██▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 7 · 2026-06 14 · 2026-07 14 · 2026-08 17 · 2026-09 16 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-0632 | 9.8 | 99.8 | KEV | Adobe ColdFusion |
| CVE-2022-22948 | 6.5 | 96.3 | KEV | VMware vCenter Server |
| CVE-2026-87886 | 7.8 | 12.9 | KEV | — |
| CVE-2024-38222 | 6.5 | 66.9 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2025-29801 | 7.8 | 63.5 | — | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability |
| CVE-2026-17497 | 8.3 | 53.3 | — | NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python |
| CVE-2026-75166 | 8.8 | 53.1 | — | — |
| CVE-2026-49157 | 8.8 | 48.2 | — | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management… |
| CVE-2026-52766 | 9.1 | 45.7 | — | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
| CVE-2024-46695 | 4.4 | 42.9 | — | selinux,smack: don't bypass permissions check in inode_setsecctx hook |
| CVE-2026-33590 | 8.5 | 41.7 | — | Insecure default permissions in Portainer CE |
| CVE-2026-77393 | 8.7 | 41.1 | — | Inductive Automation Ignition Incorrect Default Permissions |
| CVE-2026-19893 | 2.3 | 38.8 | — | D-Link DIR-842 vsftpd vsftpd.conf default permission |
| CVE-2025-8031 | 9.8 | 38.1 | — | Incorrect URL stripping in CSP reports |
| CVE-2023-54366 | 8.7 | 37.8 | — | SurrealDB before 1.0.1 Insecure Default Table Permissions |
| CVE-2026-59119 | 7.3 | 29.8 | — | PowerShell Elevation of Privilege Vulnerability |
| CVE-2026-48725 | 8.1 | 29.5 | — | Warp may allow terminal output to access the local clipboard through OSC 52 |
| CVE-2026-65940 | 6.8 | 26.5 | — | WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privil… |
| CVE-2026-8487 | 7.5 | 25.6 | — | Incorrect default permissions vulnerability in Progress Software MOVEit Automation |
| CVE-2026-86359 | 8.5 | 23.1 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 5 |
| red hat | 4 |
| microsoft | 3 |
| xen | 3 |
| amd | 2 |
| apple | 2 |
| bizerba se & co. kg | 2 |
| codesys | 2 |
| lenovo | 2 |
| otrs | 2 |
| progress | 2 |
| rockwell automation | 2 |
| surrealdb | 2 |
| watchguard | 2 |
| absolute security | 1 |