Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-303
Weakness type CWE-303 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 27 | 2 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▄▄█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 4 · 2026-09 11 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-7593 | 9.8 | 100.0 | KEV | Ivanti Virtual Traffic Manager |
| CVE-2023-29357 | 9.8 | 100.0 | KEV | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-12773 | 5.5 | 62.1 | — | BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication |
| CVE-2026-29515 | 9.3 | 60.3 | — | MiCode FileExplorer SwiFTP Server Authentication Bypass |
| CVE-2026-11430 | 6.9 | 60.1 | — | Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit |
| CVE-2026-41103 | 9.1 | 55.0 | — | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability |
| CVE-2026-47300 | 8.8 | 54.3 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50360 | 8.8 | 54.3 | — | Windows SMB Server Elevation of Privilege Vulnerability |
| CVE-2026-50627 | 9.1 | 54.2 | — | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator |
| CVE-2026-57852 | 6.3 | 51.0 | — | Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check |
| CVE-2026-10050 | 8.7 | 48.5 | — | Digest authentication lossy encoding |
| CVE-2026-49467 | 8.8 | 47.8 | — | TOTP enrollment hijack: password gate skipped due to unawaited promise |
| CVE-2026-66028 | 7.1 | 47.5 | — | Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email |
| CVE-2026-59309 | 9.8 | 47.4 | — | vCenter authentication-bypass vulnerability |
| CVE-2026-46389 | 9.8 | 45.1 | — | UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretA… |
| CVE-2026-3869 | 9.2 | 43.7 | — | — |
| CVE-2026-41053 | 8.8 | 42.4 | — | Over-inclusive team membership expansion in GitHub App authentication provider for Rancher |
| CVE-2026-46595 | 10.0 | 40.9 | — | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh |
| CVE-2026-73458 | 9.2 | 32.0 | — | On affected platforms running Arista EOS with authenticated Bidirectional Forwarding De… |
| CVE-2026-66411 | 6.9 | 30.8 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 4 |
| arista networks | 2 |
| hitachi energy | 2 |
| trilby media | 2 |
| apache | 1 |
| berriai | 1 |
| bitwarden | 1 |
| creativeitem | 1 |
| defenseunicorns | 1 |
| eclipse foundation | 1 |
| ecovacs robotics | 1 |
| golang.org/x/crypto | 1 |
| ivanti | 1 |
| micode | 1 |
| mitsubishi electric | 1 |