Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-280
Weakness type CWE-280 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 35 | 34 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▃▄▅▄█▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 5 · 2026-09 12 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-29748 | 7.8 | 50.4 | KEV | Android Pixel |
| CVE-2026-20817 | 7.8 | 92.6 | — | Windows Error Reporting Service Elevation of Privilege Vulnerability |
| CVE-2026-2340 | 6.5 | 59.7 | — | Samba: vfs_worm does not block directory modification |
| CVE-2026-40371 | 8.8 | 54.5 | — | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-73239 | 6.5 | 48.2 | — | Apache Allura: Missing permission checks IDOR |
| CVE-2026-9792 | 6.5 | 38.2 | — | Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition |
| CVE-2026-62393 | 4.3 | 37.4 | — | Apache Kylin: Improper authorization in job information retrieval |
| CVE-2026-18860 | 8.7 | 36.5 | — | Velociraptor incorrect Org deletion permissions check |
| CVE-2026-56729 | 2.1 | 29.5 | — | Zammad: Titles of knowledge base answers will be shown across all categories via the gl… |
| CVE-2026-41566 | 9.4 | 28.2 | — | Apache Kvrocks: Improper permission for the APPLYBATCH command |
| CVE-2026-55468 | 4.3 | 25.6 | — | Wagtail: Improper restriction handling on Pages admin API |
| CVE-2026-54261 | 6.5 | 25.4 | — | Wagtail: Improper permission handling in image preview |
| CVE-2026-58416 | 7.1 | 22.1 | — | Fork-PR Actions task can read a third private repository via the collaborative-owner br… |
| CVE-2026-27910 | 7.8 | 20.6 | — | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-69907 | 7.8 | 20.6 | — | Windows Enterprise App Management Elevation of Privilege Vulnerability |
| CVE-2026-54259 | 4.3 | 17.6 | — | Wagtail: Improper restriction handling on Documents and Images chosen endpoints |
| CVE-2026-54262 | 4.3 | 17.6 | — | Wagtail: Pages translations can be created without page permissions when using simple_t… |
| CVE-2026-10549 | 5.3 | 17.3 | — | Privilege escalation in Yandex Database |
| CVE-2026-1759 | 6.5 | 16.1 | — | — |
| CVE-2026-54471 | 3.5 | 14.2 | — | — |