Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-287
Weakness type CWE-287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 846 | 801 | 43 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▆▆█▁
2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 3 · 2026-03 1 · 2026-04 4 · 2026-05 36 · 2026-06 106 · 2026-07 197 · 2026-08 177 · 2026-09 258 · 2026-10 18
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-35078 | 9.8 | 100.0 | KEV | Ivanti Endpoint Manager Mobile (EPMM) |
| CVE-2024-7593 | 9.8 | 100.0 | KEV | Ivanti Virtual Traffic Manager |
| CVE-2017-7921 | 9.8 | 100.0 | KEV | Hikvision Multiple Products |
| CVE-2021-33044 | 9.8 | 100.0 | KEV | Dahua IP Camera Firmware |
| CVE-2023-46805 | 8.2 | 100.0 | KEV | Ivanti Connect Secure and Policy Secure |
| CVE-2022-40684 | 9.8 | 100.0 | KEV | Fortinet Multiple Products |
| CVE-2020-0688 | 8.8 | 100.0 | KEV | Microsoft Exchange Server |
| CVE-2021-39226 | 9.8 | 100.0 | KEV | Snapshot authentication bypass in grafana |
| CVE-2025-61882 | 9.8 | 100.0 | KEV | Oracle E-Business Suite |
| CVE-2021-33045 | 9.8 | 99.9 | KEV | Dahua IP Camera Firmware |
| CVE-2021-32030 | 9.8 | 99.9 | KEV | ASUS Routers |
| CVE-2025-49706 | 6.5 | 99.9 | KEV | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2024-53704 | 9.8 | 99.9 | KEV | SonicWall SonicOS |
| CVE-2013-0625 | 9.8 | 99.8 | KEV | Adobe ColdFusion |
| CVE-2018-10561 | 9.8 | 99.8 | KEV | Dasan Gigabit Passive Optical Network (GPON) Routers |
| CVE-2026-20182 | 10.0 | 99.8 | KEV | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
| CVE-2021-32648 | 8.2 | 99.8 | KEV | Account Takeover in Octobercms |
| CVE-2026-20127 | 10.0 | 99.8 | KEV | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
| CVE-2015-1187 | 9.8 | 99.7 | KEV | D-Link and TRENDnet Multiple Devices |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| oracle | 156 |
| microsoft | 32 |
| ibm | 31 |
| hewlett packard enterprise (hpe) | 15 |
| apache | 14 |
| red hat | 14 |
| apple | 11 |
| dell | 11 |
| acer | 6 |
| better-auth | 6 |
| mervinpraison | 6 |
| nextcloud | 6 |
| tenda | 6 |
| goauthentik | 5 |
| wwbn | 5 |