Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-306
Weakness type CWE-306 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1255 | 1196 | 49 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▅▇▁
2025-11 1 · 2025-12 9 · 2026-01 5 · 2026-02 4 · 2026-03 7 · 2026-04 9 · 2026-05 43 · 2026-06 165 · 2026-07 391 · 2026-08 226 · 2026-09 322 · 2026-10 24
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-3248 | 9.8 | 100.0 | KEV | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code |
| CVE-2017-10271 | 7.5 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2022-1388 | 9.8 | 100.0 | KEV | F5 BIG-IP |
| CVE-2023-21839 | 7.5 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2024-0012 | 9.3 | 100.0 | KEV | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) |
| CVE-2021-37415 | 9.8 | 100.0 | KEV | Zoho ManageEngine ServiceDesk Plus (SDP) |
| CVE-2020-13927 | 9.8 | 100.0 | KEV | Apache Airflow's Experimental API |
| CVE-2025-32433 | 10.0 | 99.9 | KEV | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE |
| CVE-2026-41940 | 9.3 | 99.9 | KEV | WebPros cPanel and WHM Authentication Bypass via Login Flow |
| CVE-2025-0108 | 8.8 | 99.9 | KEV | PAN-OS: Authentication Bypass in the Management Web Interface |
| CVE-2022-21587 | 9.8 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2020-6207 | 10.0 | 99.9 | KEV | SAP Solution Manager |
| CVE-2025-34028 | 9.3 | 99.9 | KEV | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package … |
| CVE-2019-9082 | 8.8 | 99.9 | KEV | ThinkPHP ThinkPHP |
| CVE-2026-20253 | 9.8 | 99.9 | KEV | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service … |
| CVE-2021-35587 | 9.8 | 99.9 | KEV | Oracle Fusion Middleware |
| CVE-2024-47575 | 9.8 | 99.9 | KEV | Fortinet FortiManager |
| CVE-2020-6287 | 10.0 | 99.9 | KEV | SAP NetWeaver |
| CVE-2025-4008 | 8.7 | 99.8 | KEV | Arbitrary Command Injection in Smartbedded MeteoBridge |
| CVE-2023-36846 | 5.3 | 99.8 | KEV | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to up… |