Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-290
Weakness type CWE-290 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 212 | 201 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▅▅█▂
2025-11 0 · 2025-12 1 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 7 · 2026-06 38 · 2026-07 39 · 2026-08 40 · 2026-09 67 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-4358 | 9.8 | 99.9 | KEV | Registration Authentication Bypass Vulnerability |
| CVE-2022-24112 | 9.8 | 99.9 | KEV | apisix/batch-requests plugin allows overwriting the X-REAL-IP header |
| CVE-2022-23131 | 9.1 | 99.9 | KEV | Unsafe client-side session storage leading to authentication bypass/instance takeover v… |
| CVE-2024-54085 | 10.0 | 99.1 | KEV | Redfish Authentication Bypass |
| CVE-2023-50224 | 6.5 | 96.7 | KEV | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability |
| CVE-2026-49468 | 9.5 | 87.1 | — | LiteLLM: Authentication Bypass via Host Header Injection |
| CVE-2026-55584 | 7.5 | 79.1 | — | phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP h… |
| CVE-2021-42308 | 3.1 | 70.0 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2021-43220 | 3.1 | 70.0 | — | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2026-3183 | 7.1 | 67.5 | — | Multi Factor Auth Bypass |
| CVE-2026-48567 | 9.8 | 59.1 | — | Azure HorizonDB Elevation of Privilege Vulnerability |
| CVE-2026-69843 | 10.0 | 58.3 | — | Microsoft Fabric Elevation of Privilege Vulnerability |
| CVE-2026-25119 | 7.7 | 57.2 | — | Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers |
| CVE-2026-46414 | 8.8 | 56.8 | — | Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking |
| CVE-2026-24270 | 9.8 | 55.5 | — | — |
| CVE-2021-34466 | 5.7 | 55.3 | — | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-76949 | 9.1 | 54.1 | — | Remember-me sign-in guard reads a session key that is never written in ash_authenticati… |
| CVE-2026-36537 | 9.8 | 54.0 | — | — |
| CVE-2026-7507 | 7.5 | 53.6 | — | Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to ac… |
| CVE-2023-21794 | 4.3 | 52.6 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 10 |
| openclaw | 10 |
| red hat | 8 |
| apache | 7 |
| 6 | |
| apple | 3 |
| decolua | 3 |
| dell | 3 |
| lenovo | 3 |
| miniorange | 3 |
| regularlabs.com | 3 |
| silabs.com | 3 |
| team-alembic | 3 |
| traefik | 3 |
| cisco | 2 |