Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-346
Weakness type CWE-346 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 313 | 307 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄▄▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 22 · 2026-06 77 · 2026-07 103 · 2026-08 50 · 2026-09 51 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-34291 | 9.4 | 99.8 | KEV | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE |
| CVE-2015-4495 | 8.8 | 99.3 | KEV | Mozilla Firefox |
| CVE-2025-53399 | 6.9 | 93.4 | — | — |
| CVE-2026-54069 | 9.2 | 45.7 | — | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist |
| CVE-2026-62316 | 8.8 | 41.4 | — | Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution |
| CVE-2024-14006 | 8.8 | 38.9 | — | Nagios XI < 2024R1.2.2 Host Header Injection |
| CVE-2026-16745 | 8.8 | 38.1 | — | Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without… |
| CVE-2026-42901 | 10.0 | 37.4 | — | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2024-1249 | 7.4 | 36.4 | — | Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginif… |
| CVE-2026-57989 | 7.4 | 34.9 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-59971 | 10.0 | 33.9 | — | MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticat… |
| CVE-2026-58169 | 7.7 | 33.9 | — | Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding… |
| CVE-2026-6734 | 8.8 | 30.3 | — | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-75156 | 9.1 | 29.6 | — | Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated… |
| CVE-2026-86466 | 8.1 | 28.3 | — | Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not valid… |
| CVE-2026-66318 | 8.1 | 27.5 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-47691 | 10.0 | 27.2 | — | Netty has Insufficient Bailiwick Validation for NS Records |
| CVE-2025-71214 | 7.8 | 27.2 | — | — |
| CVE-2026-20643 | 5.4 | 26.8 | — | — |
| CVE-2026-6276 | 7.5 | 26.2 | — | stale custom cookie host causes cookie leak |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 117 | |
| mozilla | 28 |
| microsoft | 15 |
| trend micro | 9 |
| apache | 5 |
| red hat | 4 |
| siyuan-note | 4 |
| electron | 3 |
| guzzle | 3 |
| mervinpraison | 3 |
| netty | 3 |
| spring | 3 |
| synology | 3 |
| timescale | 3 |
| ag-ui-protocol | 2 |