Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-283
Weakness type CWE-283 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 10 | 0 |
Monthly trend
▂▁▁▃█▁
2026-05 1 · 2026-06 0 · 2026-07 0 · 2026-08 2 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44707 | 6.8 | 37.5 | — | Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts |
| CVE-2026-85781 | 5.1 | 36.5 | — | Unverified access point ownership in Amazon EFS CSI Driver |
| CVE-2026-87912 | 5.1 | 36.3 | — | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agent… |
| CVE-2026-87913 | 5.1 | 36.3 | — | Missing S3 bucket ownership verification in the AWS Security Agent MCP server |
| CVE-2026-9745 | 6.5 | 23.4 | — | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-93853 | 7.2 | 9.9 | — | Barman snapshot backup deletion trusts unverified backup catalog metadata |
| CVE-2025-24890 | 6.8 | 7.7 | — | gix-sec safe.directory protections absent for elevated administrators |
| CVE-2026-54467 | 7.0 | 6.1 | — | — |
| CVE-2026-84386 | 5.1 | 3.1 | — | — |
| CVE-2026-15599 | 3.3 | 2.0 | — | Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| aws | 3 |
| chatwoot | 1 |
| enterprisedb | 1 |
| fortinet | 1 |
| gitoxidelabs | 1 |
| ibm | 1 |
| trustedfirmware | 1 |
| tübi̇tak bi̇lgem software technologies research institute | 1 |