Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-284
Weakness type CWE-284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 3272 | 3202 | 35 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▅▁
2025-11 1 · 2025-12 3 · 2026-01 9 · 2026-02 7 · 2026-03 5 · 2026-04 11 · 2026-05 80 · 2026-06 363 · 2026-07 901 · 2026-08 1199 · 2026-09 611 · 2026-10 16
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-27350 | 9.8 | 100.0 | KEV | PaperCut MF/NG |
| CVE-2019-1653 | 7.5 | 100.0 | KEV | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability |
| CVE-2023-23752 | 5.3 | 100.0 | KEV | [20230201] - Core - Improper access check in webservice endpoints |
| CVE-2023-29298 | 7.5 | 100.0 | KEV | Adobe ColdFusion Improper Access Control Security feature bypass |
| CVE-2023-38205 | 7.5 | 100.0 | KEV | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 |
| CVE-2024-27348 | 9.8 | 99.9 | KEV | Apache HugeGraph-Server: Command execution in gremlin |
| CVE-2012-4681 | 9.8 | 99.9 | KEV | Oracle Java SE |
| CVE-2024-20767 | 7.4 | 99.9 | KEV | ColdFusion | Improper Access Control (CWE-284) |
| CVE-2023-24489 | 9.8 | 99.9 | KEV | Citrix Content Collaboration |
| CVE-2023-26360 | 8.6 | 99.9 | KEV | Adobe ColdFusion Improper Access Control Arbitrary code execution |
| CVE-2013-0422 | 9.8 | 99.9 | KEV | Oracle Java Runtime Environment (JRE) |
| CVE-2011-3544 | 9.8 | 99.9 | KEV | Oracle Java SE JDK and JRE |
| CVE-2025-12480 | 9.1 | 99.9 | KEV | Gladinet Triofox |
| CVE-2022-23134 | 3.7 | 99.9 | KEV | Possible view of the setup pages by unauthenticated users if config file already exists |
| CVE-2012-1723 | 9.8 | 99.8 | KEV | Oracle Java SE |
| CVE-2016-3427 | 9.8 | 99.8 | KEV | Oracle Java SE and JRockit |
| CVE-2012-5076 | 9.8 | 99.8 | KEV | Oracle Java SE |
| CVE-2014-3120 | 8.1 | 99.8 | KEV | Elastic Elasticsearch |
| CVE-2020-8193 | 6.5 | 99.8 | KEV | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance |
| CVE-2013-2423 | 3.7 | 99.7 | KEV | Oracle Java Runtime Environment (JRE) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| oracle | 2015 |
| microsoft | 109 |
| 60 | |
| apple | 41 |
| gitea | 29 |
| joomla! project | 22 |
| sourcecodester | 18 |
| ubiquiti | 18 |
| red hat | 17 |
| dell | 16 |
| apache | 12 |
| cisco | 12 |
| regularlabs.com | 11 |
| fabrikar.com | 10 |
| ibm | 10 |