Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 486 | 464 | 16 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅█▅
2025-09 0 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 4 · 2026-05 35 · 2026-06 106 · 2026-07 197 · 2026-08 120
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-35078 | 9.8 | 100.0 | KEV | Ivanti Endpoint Manager Mobile (EPMM) |
| CVE-2023-46805 | 8.2 | 100.0 | KEV | Ivanti Connect Secure and Policy Secure |
| CVE-2022-40684 | 9.8 | 100.0 | KEV | Fortinet Multiple Products |
| CVE-2025-49706 | 6.5 | 100.0 | KEV | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2025-61882 | 9.8 | 100.0 | KEV | Oracle E-Business Suite |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2024-53704 | 9.8 | 99.9 | KEV | SonicWall SonicOS |
| CVE-2026-50751 | 9.3 | 99.6 | KEV | User Authentication Bypass in VPN Remote Access and Mobile Access |
| CVE-2026-16232 | 9.3 | 99.4 | KEV | Authentication Bypass in the SmartConsole Login Process Using an Application Token |
| CVE-2023-28461 | 9.8 | 99.3 | KEV | Array Networks AG/vxAG ArrayOS |
| CVE-2020-12812 | 9.8 | 98.8 | KEV | Fortinet FortiOS |
| CVE-2021-22893 | 10.0 | 98.7 | KEV | Ivanti Pulse Connect Secure |
| CVE-2024-49039 | 8.8 | 96.3 | KEV | Windows Task Scheduler Elevation of Privilege Vulnerability |
| CVE-2026-46817 | 9.8 | 96.1 | KEV | Oracle E-Business Suite |
| CVE-2024-21410 | 9.8 | 95.9 | KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-65400 | 9.8 | 52.2 | KEV | — |
| CVE-2026-62144 | 9.1 | 97.3 | — | Management Authentication Bypass and Privilege Escalation |
| CVE-2026-48611 | 9.8 | 89.3 | — | — |
| CVE-2026-11374 | 9.0 | 78.7 | — | Account Takeover via Predictable SSO Ticket Generation |
| CVE-2026-12571 | 9.8 | 74.3 | — | Authentication Bypass Leading to Account Takeover |
| Vendor | CVEs |
|---|---|
| oracle | 97 |
| microsoft | 29 |
| ibm | 17 |
| red hat | 9 |
| acer | 6 |
| apache | 5 |
| apple | 5 |
| better-auth | 5 |
| nextcloud | 5 |
| capgo | 4 |
| dell | 4 |
| berriai | 3 |
| checkpoint | 3 |
| code-projects | 3 |
| freescout-help-desk | 3 |