Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-425
Weakness type CWE-425 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 22 | 2 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▁▂█▄██▄
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 2 · 2026-08 5 · 2026-09 5 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-45195 | 9.8 | 100.0 | KEV | Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
| CVE-2021-26085 | 5.3 | 100.0 | KEV | Atlassian Confluence Server |
| CVE-2026-25679 | 7.5 | 56.2 | — | Incorrect parsing of IPv6 host literals in net/url |
| CVE-2026-10521 | 8.6 | 44.1 | — | Authenticated unintended access to critical program parameters |
| CVE-2026-19903 | 5.5 | 43.0 | — | SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access |
| CVE-2026-76799 | 5.5 | 43.0 | — | code-projects Login Registration System SQL Database Backup login_registration_system.s… |
| CVE-2026-78051 | 5.5 | 43.0 | — | alexta69 MeTube Cookie File cookies.txt file access |
| CVE-2026-13533 | 5.5 | 39.5 | — | agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access |
| CVE-2026-34028 | 6.9 | 38.7 | — | Unauthenticated direct access to web data in Wertheim SafeController Software exposes f… |
| CVE-2023-4018 | 4.3 | 38.0 | — | Direct Request ('Forced Browsing') in GitLab |
| CVE-2026-40532 | 6.5 | 34.3 | — | — |
| CVE-2026-60011 | 6.9 | 31.6 | — | — |
| CVE-2026-33217 | 6.5 | 28.3 | — | NATS allows MQTT clients to bypass ACL checks |
| CVE-2026-8205 | 6.3 | 26.7 | — | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block si… |
| CVE-2026-14953 | 5.3 | 23.8 | — | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to impro… |
| CVE-2026-11986 | 4.9 | 20.7 | — | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk… |
| CVE-2026-36453 | 7.4 | 17.5 | — | — |
| CVE-2026-9610 | 5.3 | 16.0 | — | Multiple Vulnerabilities in IBM Datacap |
| CVE-2024-23573 | 3.7 | 14.2 | — | — |
| CVE-2026-102583 | 2.7 | 13.9 | — | Moodle: incorrect capability check in ai generate image web service |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| hclsoftware | 2 |
| agentejo | 1 |
| alexta69 | 1 |
| apache | 1 |
| atlassian | 1 |
| code-projects | 1 |
| comelit group s.p.a | 1 |
| concrete cms | 1 |
| frauscher sensortechnik | 1 |
| gitlab | 1 |
| go standard library | 1 |
| ibm | 1 |
| kentico | 1 |
| mb connect line | 1 |
| nats-io | 1 |