Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-367
Weakness type CWE-367 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 262 | 242 | 6 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅█▇▁
2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 4 · 2026-03 0 · 2026-04 4 · 2026-05 16 · 2026-06 37 · 2026-07 38 · 2026-08 72 · 2026-09 65 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-30088 | 7.0 | 99.3 | KEV | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2023-35311 | 8.8 | 96.7 | KEV | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2015-3246 | 7.4 | 94.8 | KEV | — |
| CVE-2025-22224 | 9.3 | 74.4 | KEV | VMware ESXi and Workstation |
| CVE-2025-38352 | 7.8 | 69.2 | KEV | posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() |
| CVE-2022-48618 | 7.0 | 39.8 | KEV | Apple Multiple Products |
| CVE-2024-21371 | 7.0 | 95.7 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-30084 | 7.0 | 93.0 | — | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-20816 | 7.0 | 84.0 | — | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-53822 | 8.7 | 79.6 | — | OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval… |
| CVE-2026-21523 | 8.0 | 55.9 | — | GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-53806 | 7.7 | 47.7 | — | OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation |
| CVE-2026-78319 | 9.3 | 47.2 | — | TOCTOU Vulnerability in file exchange |
| CVE-2026-66314 | 5.3 | 45.5 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-82761 | 9.1 | 44.6 | — | Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
| CVE-2024-30099 | 7.0 | 43.7 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-19118 | 7.7 | 43.4 | — | Race condition vulnerability was identified in GitHub Enterprise Server that allowed re… |
| CVE-2026-56648 | 7.5 | 41.3 | — | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-69804 | 7.5 | 41.3 | — | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-43632 | 9.2 | 39.0 | — | llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 35 |
| 29 | |
| linux | 15 |
| ibm | 10 |
| openclaw | 9 |
| red hat | 8 |
| rsyncproject | 7 |
| apache | 5 |
| dell | 4 |
| nvidia | 4 |
| qualcomm | 4 |
| mediatek | 3 |
| mervinpraison | 3 |
| midnightbsd | 3 |
| trend micro | 3 |