Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-377
Weakness type CWE-377 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 20 | 0 |
Monthly trend
▆▃█▃▂
2026-06 6 · 2026-07 2 · 2026-08 9 · 2026-09 2 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44878 | 7.2 | 46.8 | — | Authenticated Path Traversal allows Unauthorized Access in Web Interface |
| CVE-2026-49134 | 7.5 | 39.0 | — | CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File |
| CVE-2026-54584 | 5.3 | 38.1 | — | mport trusts environment-controlled temporary directories in privileged metadata extrac… |
| CVE-2025-14602 | 5.3 | 38.1 | — | Weak File Name Generation in vsDesk |
| CVE-2026-40635 | 5.4 | 30.8 | — | — |
| CVE-2026-75920 | 6.0 | 27.3 | — | phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP |
| CVE-2026-47852 | 7.5 | 26.0 | — | Predictable cache directory location allows local ONNX model substitution in Spring AI |
| CVE-2026-53759 | 2.0 | 7.9 | — | linuxfabrik-lib: Insecure creation of SQLite databases |
| CVE-2026-49135 | 7.2 | 5.5 | — | CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow |
| CVE-2026-45384 | 6.1 | 5.5 | — | bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Arch… |
| CVE-2026-63404 | 7.3 | 4.4 | — | Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (networ… |
| CVE-2026-46406 | 4.4 | 3.9 | — | Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and S… |
| CVE-2026-73585 | 6.3 | 3.1 | — | Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registrat… |
| CVE-2026-41991 | 2.0 | 2.9 | — | Predictable Temporary File in GNU gzip |
| CVE-2026-62294 | 5.1 | 2.7 | — | Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With" |
| CVE-2026-55086 | 4.2 | 2.7 | — | Etherpad: Import/export use Math.random() for temp file paths; predictable paths on sha… |
| CVE-2026-41001 | 5.3 | 2.3 | — | Predictable Temp Directory in Artemis Auto-configuration |
| CVE-2026-73584 | 6.3 | 2.0 | — | Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure t… |
| CVE-2026-16791 | 1.0 | 2.0 | — | Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI |
| CVE-2026-79899 | 7.9 | 0.1 | — | Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 2 |
| spring | 2 |
| steipete | 2 |
| anthropics | 1 |
| contribsys | 1 |
| dell | 1 |
| ether | 1 |
| flameshot-org | 1 |
| fortra | 1 |
| gnu | 1 |
| hewlett packard enterprise (hpe) | 1 |
| lenovo | 1 |
| linuxfabrik | 1 |
| midnightbsd | 1 |
| rikyoz | 1 |