Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-36
Weakness type CWE-36 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 33 | 28 | 5 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▁▂▁▁▁▁▁▁▁▁▁▂▂▂▁▅▃▅▆█▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 6 · 2026-09 8 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-13159 | 9.8 | 100.0 | KEV | Ivanti Endpoint Manager (EPM) |
| CVE-2018-20250 | 7.8 | 99.9 | KEV | RARLAB WinRAR |
| CVE-2024-48248 | 8.6 | 99.9 | KEV | NAKIVO Backup and Replication |
| CVE-2024-13160 | 9.8 | 99.8 | KEV | Ivanti Endpoint Manager (EPM) |
| CVE-2024-13161 | 9.8 | 99.8 | KEV | Ivanti Endpoint Manager (EPM) |
| CVE-2026-89009 | 8.8 | 61.9 | — | WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server |
| CVE-2026-49290 | 7.6 | 56.2 | — | Slopsmith has path traversal in archive extractors that allows arbitrary file write → p… |
| CVE-2026-82092 | 6.5 | 54.2 | — | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-20834 | 4.6 | 53.4 | — | Windows Spoofing Vulnerability |
| CVE-2026-47606 | 9.1 | 53.0 | — | — |
| CVE-2026-15302 | 5.3 | 52.2 | — | ARMember <= 4.0.27 - Directory Traversal via X-FILENAME |
| CVE-2026-68487 | 9.9 | 49.2 | — | — |
| CVE-2026-32175 | 4.3 | 48.7 | — | .NET Core Tampering Vulnerability |
| CVE-2026-57211 | 10.0 | 48.4 | — | RabbitMQ: UNC SSRF affecting the management UI on Windows |
| CVE-2026-10044 | 8.2 | 46.9 | — | ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/ |
| CVE-2026-88288 | 6.5 | 44.0 | — | GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation |
| CVE-2026-61891 | 7.5 | 43.0 | — | — |
| CVE-2026-0846 | 8.6 | 42.8 | — | Arbitrary File Read via Absolute Path Input in nltk.util.filestring() |
| CVE-2026-26337 | 8.8 | 41.9 | — | Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and … |
| CVE-2026-53698 | 6.5 | 39.3 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 5 |
| ivanti | 3 |
| nvidia | 2 |
| byrongamatos | 1 |
| check point | 1 |
| eclipse foundation | 1 |
| geovision | 1 |
| hyland | 1 |
| ibm | 1 |
| interinfo | 1 |
| kata-containers | 1 |
| nakivo | 1 |
| nltk | 1 |
| oscal-compass | 1 |
| progress | 1 |