Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-426
Weakness type CWE-426 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 76 | 68 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▂▆▅█▆▁
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 2 · 2026-03 1 · 2026-04 2 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 19 · 2026-09 13 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2012-1854 | 7.8 | 97.5 | KEV | Microsoft Visual Basic for Applications (VBA) |
| CVE-2022-22047 | 7.8 | 97.2 | KEV | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
| CVE-2024-30100 | 7.8 | 66.7 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2025-27743 | 7.8 | 57.8 | — | Microsoft System Center Elevation of Privilege Vulnerability |
| CVE-2026-63093 | 8.7 | 56.6 | — | Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace |
| CVE-2024-35260 | 9.8 | 56.0 | — | Microsoft Dataverse Remote Code Execution Vulnerability |
| CVE-2024-43616 | 7.8 | 54.2 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55769 | 9.4 | 54.1 | — | CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG f… |
| CVE-2026-16674 | 8.8 | 53.2 | — | IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty |
| CVE-2026-45721 | 9.0 | 53.1 | — | Algernon: handler.lua discovery walks parent directories above the server root |
| CVE-2023-36898 | 7.8 | 52.1 | — | Tablet Windows User Interface Application Core Remote Code Execution Vulnerability |
| CVE-2026-74872 | 9.3 | 50.7 | — | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool |
| CVE-2026-20943 | 7.0 | 49.9 | — | Microsoft Office Click-To-Run Remote Code Execution Vulnerability |
| CVE-2026-42830 | 6.5 | 49.1 | — | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability |
| CVE-2026-78155 | 9.9 | 42.0 | — | Untrusted Search Path in StackGres |
| CVE-2026-44477 | 9.4 | 41.8 | — | CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and… |
| CVE-2026-57097 | 6.8 | 40.8 | — | Microsoft XML Security Feature Bypass Vulnerability |
| CVE-2024-43576 | 7.8 | 40.2 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-49145 | 7.5 | 39.8 | — | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a pr… |
| CVE-2026-56174 | 7.8 | 37.5 | — | Windows Narrator Braille Elevation of Privilege Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 16 |
| adobe | 10 |
| openclaw | 6 |
| ibm | 3 |
| aws | 2 |
| cloudnative-pg | 2 |
| jahlives | 2 |
| open-telemetry | 2 |
| palo alto networks | 2 |
| anysphere | 1 |
| apache | 1 |
| artifex software | 1 |
| b&r industrial automation | 1 |
| checkmal | 1 |
| eai technologies | 1 |