Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-281
Weakness type CWE-281 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 24 | 22 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▃▃▃█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 3 · 2026-07 2 · 2026-08 2 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-8543 | 9.8 | 99.5 | KEV | Microsoft Windows |
| CVE-2024-1726 | 5.3 | 52.5 | — | Quarkus: security checks for some inherited endpoints performed after serialization in … |
| CVE-2026-39832 | 9.1 | 52.1 | — | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent |
| CVE-2026-35385 | 8.1 | 48.5 | — | — |
| CVE-2026-39828 | 6.3 | 43.4 | — | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh |
| CVE-2026-4360 | 2.0 | 39.3 | — | Tarfile.extract() doesn't fully respect filter parameter |
| CVE-2026-44832 | 8.7 | 36.2 | — | Snipe-IT: Privilege Escalation via API Permissions Assignment |
| CVE-2026-40767 | 7.5 | 31.2 | — | WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability |
| CVE-2026-44947 | 6.9 | 30.6 | — | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher |
| CVE-2026-61709 | 5.3 | 26.5 | — | OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-in… |
| CVE-2026-58510 | 4.3 | 24.0 | — | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code… |
| CVE-2025-14779 | 3.8 | 22.5 | — | Improper Access Control via Secret Type Management API in WSO2 Identity Server |
| CVE-2024-47270 | 2.7 | 14.8 | — | — |
| CVE-2026-88016 | 7.1 | 7.5 | — | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in r… |
| CVE-2026-58494 | 6.5 | 5.9 | — | Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination |
| CVE-2026-23556 | 9.4 | 5.6 | — | oxenstored keeps quota related use counts across domain destruction |
| CVE-2026-82964 | 8.8 | 4.2 | — | Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx… |
| CVE-2026-24194 | 7.8 | 3.7 | — | — |
| CVE-2026-47596 | 7.0 | 3.1 | — | — |
| CVE-2026-93658 | 7.3 | 2.7 | — | uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| nvidia | 5 |
| golang.org/x/crypto | 2 |
| bytecodealliance | 1 |
| gen digital | 1 |
| gitea | 1 |
| grokability | 1 |
| hashicorp | 1 |
| microsoft | 1 |
| openbsd | 1 |
| openfga | 1 |
| python software foundation | 1 |
| rclone | 1 |
| red hat | 1 |
| suse | 1 |
| synology | 1 |