Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-359
Weakness type CWE-359 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 40 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▂▂▁▁▂▆▄▄█▁
2025-11 1 · 2025-12 1 · 2026-01 1 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 10 · 2026-07 6 · 2026-08 6 · 2026-09 13 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-26192 | 8.2 | 73.5 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-20834 | 4.6 | 53.4 | — | Windows Spoofing Vulnerability |
| CVE-2026-56171 | 7.5 | 49.8 | — | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2019-25762 | 8.7 | 49.7 | — | Joomla! Component JoomProject 1.1.3.2 Information Disclosure |
| CVE-2026-48048 | 7.5 | 49.4 | — | XWiki Platform's Livetable results still allow reconstructing password hashes using 768… |
| CVE-2026-56124 | 8.7 | 48.7 | — | phpUploader < 2.0.2 Unauthenticated Database Exposure via index model |
| CVE-2026-62328 | 8.7 | 48.1 | — | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints |
| CVE-2020-37173 | 8.7 | 46.9 | — | AVideo Platform 8.1 - Information Disclosure (User Enumeration) |
| CVE-2026-25699 | 6.1 | 45.4 | — | Apache Answer: Authorization Bypass in Timeline API |
| CVE-2026-58296 | 7.1 | 43.6 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-58297 | 7.1 | 43.5 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2025-43496 | 7.5 | 39.9 | — | — |
| CVE-2026-0102 | 3.1 | 39.3 | — | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability |
| CVE-2026-26237 | 6.6 | 39.2 | — | QuMagie |
| CVE-2026-69351 | 5.5 | 39.1 | — | Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability |
| CVE-2026-73008 | 5.5 | 39.1 | — | Windows Biometric Service Information Disclosure Vulnerability |
| CVE-2026-92565 | 6.9 | 37.8 | — | Rallly before 4.15.0 Information Disclosure via polls.get |
| CVE-2026-74966 | 7.5 | 35.9 | — | Information disclosure in the Form Autofill component |
| CVE-2026-57960 | 8.3 | 35.0 | — | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id |
| CVE-2026-86904 | 7.5 | 34.9 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 9 |
| apple | 6 |
| angular | 1 |
| apache | 1 |
| avideo | 1 |
| cenodude | 1 |
| cloudreve | 1 |
| decolua | 1 |
| digital operations services | 1 |
| djust-org | 1 |
| edwardkim | 1 |
| gitea | 1 |
| hclsoftware | 1 |
| hellotalk | 1 |
| hieventsdev | 1 |