Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-305
Weakness type CWE-305 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 36 | 33 | 3 |
Monthly trend
▂▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▃▁▅▄▆█▆▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 4 · 2026-07 7 · 2026-08 9 · 2026-09 6 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-31161 | 9.8 | 100.0 | KEV | CrushFTP CrushFTP |
| CVE-2026-81578 | 8.8 | 99.7 | KEV | PaperCut MF/NG: Authentication Bypass |
| CVE-2024-37085 | 6.8 | 98.0 | KEV | VMware ESXi |
| CVE-2026-25555 | 9.3 | 85.6 | — | OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header |
| CVE-2026-86207 | 7.7 | 68.4 | — | Authentication bypass leads to unauthorised access to N-central |
| CVE-2026-19349 | 9.8 | 55.7 | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, fro… |
| CVE-2026-85500 | 9.1 | 54.0 | — | `require_confirmed_with` is not enforced on the action and fails open on an unreadable … |
| CVE-2023-4501 | 9.8 | 53.6 | — | Authentication bypass in OpenText (Micro Focus) Enterprise Server |
| CVE-2026-78619 | 9.8 | 47.9 | — | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code… |
| CVE-2026-6266 | 8.3 | 45.4 | — | Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified e… |
| CVE-2025-14600 | 9.3 | 41.7 | — | Admin Account Takeover via Path Traversal in vsDesk |
| CVE-2026-5545 | 6.5 | 41.4 | — | wrong reuse of HTTP Negotiate connection |
| CVE-2026-77185 | 9.1 | 41.0 | — | Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
| CVE-2026-9798 | 4.3 | 40.0 | — | Keycloak: keycloak: brute-force protection bypass in ciba flow |
| CVE-2026-3784 | 6.5 | 37.0 | — | wrong proxy connection reuse with credentials |
| CVE-2026-10539 | 9.5 | 34.4 | — | Unauthenticated command injection in Control-M/Server communication command |
| CVE-2026-41052 | 9.4 | 34.4 | — | Rancher Privilege Escalation from Project Owner to Host |
| CVE-2026-62427 | 8.8 | 33.8 | — | sysctl and platform-op locks open to abuse |
| CVE-2026-1621 | 5.3 | 32.4 | — | Register Bypass in Universal Sotware's E-Municipality |
| CVE-2026-8932 | 7.5 | 31.5 | — | incomplete mTLS config matching in conn reuse |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| curl | 4 |
| red hat | 4 |
| apache | 3 |
| mattermost | 2 |
| silabs.com | 2 |
| suse | 2 |
| abb | 1 |
| bmc | 1 |
| crushftp | 1 |
| dell | 1 |
| devolutions | 1 |
| n-able | 1 |
| openbullet | 1 |
| opentext | 1 |
| papercut | 1 |