Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-345
Weakness type CWE-345 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 256 | 249 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅██▁
2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 11 · 2026-06 30 · 2026-07 48 · 2026-08 75 · 2026-09 77 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-38831 | 7.8 | 100.0 | KEV | RARLAB WinRAR |
| CVE-2022-26871 | 9.8 | 97.3 | KEV | Trend Micro Apex Central |
| CVE-2026-21527 | 6.5 | 94.7 | — | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-85431 | 8.7 | 86.2 | — | MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection |
| CVE-2026-85430 | 8.8 | 69.6 | — | MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing |
| CVE-2026-28324 | 9.8 | 49.5 | — | SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability |
| CVE-2026-18674 | 7.0 | 44.5 | — | Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an un… |
| CVE-2026-71965 | 8.7 | 38.7 | — | CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature |
| CVE-2026-62869 | 8.8 | 36.3 | — | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-62874 | 10.0 | 34.8 | — | Azure Billing Elevation of Privilege Vulnerability |
| CVE-2025-27735 | 6.0 | 32.3 | — | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
| CVE-2026-18248 | 9.1 | 29.5 | — | @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigate… |
| CVE-2026-44725 | 6.6 | 28.9 | — | EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code exe… |
| CVE-2026-47691 | 10.0 | 27.2 | — | Netty has Insufficient Bailiwick Validation for NS Records |
| CVE-2026-26007 | 8.2 | 25.9 | — | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves |
| CVE-2026-73840 | 5.3 | 25.9 | — | OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook … |
| CVE-2025-12999 | 9.1 | 25.3 | — | — |
| CVE-2026-53561 | 7.4 | 25.1 | — | Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-toke… |
| CVE-2026-9242 | 5.3 | 25.0 | — | RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Fo… |
| CVE-2026-54239 | 8.8 | 23.1 | — | FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 7 |
| apache | 6 |
| red hat | 6 |
| better-auth | 5 |
| gitroomhq | 5 |
| jahlives | 5 |
| eclipse foundation | 4 |
| wwbn | 4 |
| zcashfoundation | 4 |
| arista networks | 3 |
| corewcf | 3 |
| jpadilla | 3 |
| legion of the bouncy castle | 3 |
| midnightbsd | 3 |
| moos-ivp | 3 |