Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-352
Weakness type CWE-352 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 615 | 601 | 6 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇█▇█▂
2025-11 1 · 2025-12 3 · 2026-01 2 · 2026-02 2 · 2026-03 6 · 2026-04 3 · 2026-05 77 · 2026-06 111 · 2026-07 131 · 2026-08 117 · 2026-09 135 · 2026-10 17
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2016-6277 | 8.8 | 100.0 | KEV | NETGEAR Multiple Routers |
| CVE-2025-62593 | 9.4 | 99.2 | KEV | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack |
| CVE-2014-100005 | 8.0 | 98.7 | KEV | D-Link DIR-600 Router |
| CVE-2008-4128 | 8.1 | 98.4 | KEV | Cisco IOS |
| CVE-2023-2533 | 8.4 | 98.1 | KEV | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF |
| CVE-2020-10181 | 9.8 | 96.6 | KEV | Sumavision Enhanced Multimedia Router (EMR) |
| CVE-2020-1103 | 6.5 | 83.3 | — | Microsoft SharePoint Information Disclosure Vulnerability |
| CVE-2026-75743 | 7.1 | 73.3 | — | Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352) |
| CVE-2026-8174 | 5.7 | 50.6 | — | Cross-site Request Forgery |
| CVE-2021-41372 | 7.6 | 50.5 | — | Power BI Report Server Spoofing Vulnerability |
| CVE-2026-19650 | 7.1 | 47.6 | — | Cross-Site Request Forgery (CSRF) in GitLab |
| CVE-2026-56660 | 9.1 | 42.7 | — | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction |
| CVE-2026-14620 | 4.7 | 42.2 | — | webpack-dev-server vulnerable to cross-site request forgery via internal developer endp… |
| CVE-2026-60009 | 8.8 | 36.4 | — | — |
| CVE-2024-21381 | 6.8 | 34.1 | — | Microsoft Azure Active Directory B2C Spoofing Vulnerability |
| CVE-2026-15070 | 8.8 | 31.9 | — | Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution … |
| CVE-2026-44613 | 6.1 | 30.5 | — | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling |
| CVE-2026-71694 | 8.8 | 29.9 | — | — |
| CVE-2026-88061 | 5.8 | 29.1 | — | career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowi… |
| CVE-2026-49471 | 8.3 | 28.9 | — | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory po… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| oracle | 43 |
| concrete cms | 31 |
| 27 | |
| wwbn | 19 |
| jenkins project | 13 |
| misp | 11 |
| cotonti | 9 |
| ibm | 9 |
| regularlabs.com | 7 |
| admidio | 6 |
| apache | 6 |
| yeswiki | 6 |
| joomshaper.com | 5 |
| mybb | 5 |
| sourcecodester | 5 |