Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-427
Weakness type CWE-427 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 97 | 88 | 2 |
Monthly trend
▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▃█▅█▆▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 7 · 2026-06 23 · 2026-07 14 · 2026-08 24 · 2026-09 17 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-3153 | 6.5 | 98.1 | KEV | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability |
| CVE-2020-3433 | 7.8 | 95.5 | KEV | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability |
| CVE-2026-55015 | 5.5 | 60.9 | — | Microsoft Remote Help Denial of Service Vulnerability |
| CVE-2025-29802 | 7.3 | 59.9 | — | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2025-29817 | 5.7 | 58.2 | — | Microsoft Power Automate Desktop Information Disclosure Vulnerability |
| CVE-2026-65093 | 9.9 | 55.2 | — | — |
| CVE-2025-29803 | 7.3 | 53.4 | — | Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Priv… |
| CVE-2026-16860 | 9.9 | 53.2 | — | IBM i is Affected By Remote Code Execution Vulnerability [] |
| CVE-2026-54916 | 8.8 | 47.4 | — | NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missi… |
| CVE-2026-72980 | 5.5 | 45.4 | — | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-32172 | 8.0 | 45.1 | — | Microsoft Power Apps Remote Code Execution Vulnerability |
| CVE-2026-54232 | 8.8 | 44.8 | — | vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile |
| CVE-2022-36271 | 7.8 | 41.5 | — | — |
| CVE-2026-7870 | 8.8 | 40.0 | — | IBM i is Affected by Privilege Escalation [] |
| CVE-2026-55013 | 7.1 | 38.0 | — | Windows Remote Help Defense Spoofing Vulnerability |
| CVE-2025-10939 | 3.7 | 33.0 | — | Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console |
| CVE-2026-44358 | 8.2 | 22.4 | — | Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint |
| CVE-2026-34632 | 8.6 | 21.5 | — | Photoshop Installer | CWE-427: Uncontrolled Search Path Element |
| CVE-2026-48388 | 8.6 | 21.1 | — | Photoshop Installer | CWE-427: Uncontrolled Search Path Element |
| CVE-2026-76199 | 8.6 | 19.9 | — | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) |