Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-347
Weakness type CWE-347 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 251 | 241 | 7 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▃▅▇█▂
2025-11 0 · 2025-12 2 · 2026-01 1 · 2026-02 1 · 2026-03 9 · 2026-04 3 · 2026-05 8 · 2026-06 26 · 2026-07 41 · 2026-08 68 · 2026-09 74 · 2026-10 10
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-59718 | 9.1 | 99.3 | KEV | Fortinet Multiple Products |
| CVE-2013-3900 | 5.5 | 98.7 | KEV | WinVerifyTrust Signature Validation Vulnerability |
| CVE-2020-1464 | 7.8 | 98.6 | KEV | Windows Spoofing Vulnerability |
| CVE-2026-48558 | 9.5 | 92.8 | KEV | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification |
| CVE-2025-47827 | 4.6 | 91.9 | KEV | IGEL IGEL OS |
| CVE-2020-2021 | 10.0 | 91.0 | KEV | PAN-OS: Authentication Bypass in SAML Authentication |
| CVE-2026-5430 | 10.0 | 46.3 | KEV | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Accou… |
| CVE-2025-59719 | 9.1 | 98.1 | — | — |
| CVE-2026-67276 | 9.2 | 93.5 | — | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-10795 | 8.1 | 89.2 | — | UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication By… |
| CVE-2024-8698 | 7.7 | 80.4 | — | Keycloak-saml-core: improper verification of saml responses leading to privilege escala… |
| CVE-2026-47212 | 6.9 | 73.5 | — | Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Una… |
| CVE-2026-15013 | 9.8 | 73.4 | — | SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse'… |
| CVE-2026-12263 | 8.8 | 71.5 | — | Authentication Bypass |
| CVE-2026-54733 | 9.3 | 57.6 | — | moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endp… |
| CVE-2026-40372 | 9.1 | 55.9 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-10754 | 8.6 | 54.3 | — | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of c… |
| CVE-2026-50010 | 7.5 | 52.3 | — | Netty's wrapping plain trust manager silently disables hostname verification |
| CVE-2026-5588 | 6.3 | 51.0 | — | PKIX draft CompositeVerifier accepts empty signature sequence as valid. |
| CVE-2026-9779 | 7.2 | 50.7 | — | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Rem… |