Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-427 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 73 | 65 | 2 |
▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▃█▅▇
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 6 · 2026-06 23 · 2026-07 14 · 2026-08 20
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-3153 | 6.5 | 97.9 | KEV | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability |
| CVE-2020-3433 | 7.8 | 95.2 | KEV | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability |
| CVE-2025-29802 | 7.3 | 57.1 | — | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2025-29817 | 5.7 | 54.6 | — | Microsoft Power Automate Desktop Information Disclosure Vulnerability |
| CVE-2025-29803 | 7.3 | 51.0 | — | Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Priv… |
| CVE-2026-54232 | 8.8 | 44.3 | — | vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile |
| CVE-2026-16860 | 9.9 | 41.5 | — | IBM i is Affected By Remote Code Execution Vulnerability [] |
| CVE-2022-36271 | 7.8 | 40.6 | — | — |
| CVE-2025-10939 | 3.7 | 31.3 | — | Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console |
| CVE-2026-7870 | 8.8 | 27.4 | — | IBM i is Affected by Privilege Escalation [] |
| CVE-2026-32172 | 8.0 | 26.5 | — | Microsoft Power Apps Remote Code Execution Vulnerability |
| CVE-2026-34632 | 8.6 | 19.7 | — | Photoshop Installer | CWE-427: Uncontrolled Search Path Element |
| CVE-2025-30033 | 8.5 | 10.9 | — | — |
| CVE-2026-18718 | 7.1 | 11.0 | — | Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State |
| CVE-2025-41670 | 8.7 | 9.0 | — | Untrusted Search Path |
| CVE-2026-44358 | 8.2 | 8.0 | — | Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint |
| CVE-2026-38972 | 7.8 | 8.0 | — | — |
| CVE-2026-6645 | 7.3 | 7.7 | — | Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows |
| CVE-2026-48388 | 8.6 | 7.0 | — | Photoshop Installer | CWE-427: Uncontrolled Search Path Element |
| CVE-2026-57239 | 7.8 | 6.7 | — | Foxit PDF Editor/Reader Local Privilege Escalation |