Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-358
Weakness type CWE-358 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 20 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁█▅▅▁▂▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 9 · 2026-06 5 · 2026-07 5 · 2026-08 0 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-7965 | 8.8 | 97.2 | KEV | Google Chromium V8 |
| CVE-2026-50628 | 9.8 | 62.2 | — | Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control |
| CVE-2026-44513 | 8.8 | 58.0 | — | Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components |
| CVE-2026-45109 | 7.5 | 53.8 | — | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes |
| CVE-2023-4501 | 9.8 | 53.6 | — | Authentication bypass in OpenText (Micro Focus) Enterprise Server |
| CVE-2026-40597 | 7.6 | 46.2 | — | MantisBT has a Content Security Policy bypass via attachments |
| CVE-2026-48797 | 9.3 | 45.1 | — | Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication |
| CVE-2026-57915 | 7.3 | 42.5 | — | Apache Kerby: Kerberos Pre-Authentication Bypass |
| CVE-2026-12577 | 8.7 | 34.8 | — | DVP80ES3 Improperly Implemented Security Check for Standard vulnerability |
| CVE-2026-65058 | 5.9 | 31.7 | — | Trezor Safe improper security check in on-device display |
| CVE-2026-42082 | 5.4 | 30.2 | — | free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover |
| CVE-2024-55599 | 4.9 | 28.1 | — | — |
| CVE-2026-49783 | 7.8 | 24.4 | — | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-42081 | 7.1 | 19.0 | — | free5GC: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-96760 | 9.8 | 18.4 | — | Authlib library contains a signature‑verification bypass vulnerability |
| CVE-2026-44473 | 7.1 | 17.3 | — | Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse |
| CVE-2026-44475 | 6.1 | 12.2 | — | Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-44474 | 3.7 | 9.0 | — | Ella Core: Handover failures during concurrent Security Mode Command |
| CVE-2026-46582 | 3.7 | 7.7 | — | A wildcard replay, as another piece of data, triggers poisoning in the serve expired re… |
| CVE-2026-54431 | 5.1 | 6.7 | — | Improper Data Validation in liboauth2 |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ellanetworks | 3 |
| 3 | |
| apache | 2 |
| free5gc | 2 |
| apple | 1 |
| authlib | 1 |
| deltaww | 1 |
| fortinet | 1 |
| huggingface | 1 |
| mantisbt | 1 |
| mcp-tool-shop-org | 1 |
| microsoft | 1 |
| nlnet labs | 1 |
| openidc | 1 |
| opentext | 1 |