Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-295
Weakness type CWE-295 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 274 | 265 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▃▆█▂
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 2 · 2026-03 5 · 2026-04 3 · 2026-05 23 · 2026-06 35 · 2026-07 32 · 2026-08 60 · 2026-09 90 · 2026-10 13
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-0601 | 8.1 | 99.8 | KEV | Microsoft Windows |
| CVE-2022-26923 | 8.8 | 99.7 | KEV | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2023-41991 | 5.5 | 96.3 | KEV | Apple Multiple Products |
| CVE-2026-85102 | 9.8 | 94.3 | KEV | Improper Certificate Validation in Quantum Security Gateway |
| CVE-2023-20963 | 7.8 | 72.8 | KEV | Android Framework |
| CVE-2020-1113 | 5.3 | 93.2 | — | Windows Task Scheduler Security Feature Bypass Vulnerability |
| CVE-2026-18129 | 8.1 | 72.6 | — | — |
| CVE-2025-32989 | 5.3 | 70.9 | — | Gnutls: vulnerability in gnutls sct extension parsing |
| CVE-2026-8992 | 8.8 | 66.2 | — | — |
| CVE-2024-43550 | 7.4 | 64.4 | — | Windows Secure Channel Spoofing Vulnerability |
| CVE-2026-11814 | 4.9 | 58.7 | — | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers |
| CVE-2026-43869 | 7.3 | 55.4 | — | Apache Thrift: TSSLTransportFactory.java hostname verification |
| CVE-2026-21228 | 8.1 | 54.2 | — | Azure Local Remote Code Execution Vulnerability |
| CVE-2025-14819 | 5.3 | 53.0 | — | OpenSSL partial chain store policy bypass |
| CVE-2026-27137 | 7.5 | 51.0 | — | Incorrect enforcement of email constraints in crypto/x509 |
| CVE-2026-39835 | 5.3 | 49.9 | — | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh |
| CVE-2026-42508 | 9.1 | 49.6 | — | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts |
| CVE-2026-42011 | 7.4 | 45.2 | — | Gnutls: gnutls: security bypass due to incorrect name constraint handling |
| CVE-2026-55215 | 7.5 | 45.2 | — | MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `s… |
| CVE-2026-42013 | 8.2 | 44.9 | — | Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 29 |
| wolfssl | 15 |
| red hat | 13 |
| ibm | 11 |
| apache | 10 |
| curl | 8 |
| microsoft | 8 |
| legion of the bouncy castle | 7 |
| eclipse foundation | 4 |
| erlang | 4 |
| open ises | 4 |
| adobe | 3 |
| apple | 3 |
| devolutions | 3 |
| ecovacs robotics | 3 |