Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-288
Weakness type CWE-288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 176 | 159 | 20 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▁▁▁▁▁▁▂▁▂▁▅▇▅█▆▁
2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 4 · 2026-04 0 · 2026-05 22 · 2026-06 36 · 2026-07 24 · 2026-08 40 · 2026-09 29 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-42793 | 9.8 | 100.0 | KEV | JetBrains TeamCity |
| CVE-2024-1709 | 10.0 | 100.0 | KEV | Authentication bypass using an alternate path or channel |
| CVE-2024-27198 | 9.8 | 100.0 | KEV | JetBrains TeamCity |
| CVE-2025-4427 | 5.3 | 100.0 | KEV | Authentication Bypass |
| CVE-2025-2747 | 9.8 | 99.9 | KEV | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass |
| CVE-2026-23760 | 9.3 | 99.9 | KEV | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API |
| CVE-2023-46747 | 9.8 | 99.9 | KEV | BIG-IP Configuration utility unauthenticated remote code execution vulnerability |
| CVE-2024-55591 | 9.8 | 99.8 | KEV | Fortinet FortiOS and FortiProxy |
| CVE-2020-10148 | 9.8 | 99.8 | KEV | SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remot… |
| CVE-2026-20079 | 10.0 | 99.8 | KEV | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vul… |
| CVE-2026-1603 | 8.6 | 99.8 | KEV | Ivanti Endpoint Manager (EPM) |
| CVE-2026-24858 | 9.4 | 99.7 | KEV | Fortinet Multiple Products |
| CVE-2025-57819 | 10.0 | 99.7 | KEV | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE |
| CVE-2025-34026 | 9.2 | 99.6 | KEV | Versa Concerto Actuator Authentication Bypass Information Leak |
| CVE-2025-2746 | 9.8 | 99.4 | KEV | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass |
| CVE-2023-20269 | 9.1 | 97.9 | KEV | Cisco Adaptive Security Appliance and Firepower Threat Defense |
| CVE-2026-19490 | 9.3 | 97.7 | KEV | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 |
| CVE-2026-18577 | 8.2 | 96.6 | KEV | Incomplete patch leads to administrative account takeover |
| CVE-2026-18556 | 8.2 | 94.5 | KEV | Unauthenticated administrative account takeover |
| CVE-2025-24472 | 8.1 | 94.2 | KEV | Fortinet FortiOS and FortiProxy |