boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-427

Weakness type CWE-427 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
97882

Monthly trend

▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▃█▅█▆▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 7 · 2026-06 23 · 2026-07 14 · 2026-08 24 · 2026-09 17 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-31536.598.1KEVCisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
CVE-2020-34337.895.5KEVCisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
CVE-2026-550155.560.9—Microsoft Remote Help Denial of Service Vulnerability
CVE-2025-298027.359.9—Visual Studio Elevation of Privilege Vulnerability
CVE-2025-298175.758.2—Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2026-650939.955.2——
CVE-2025-298037.353.4—Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Priv…
CVE-2026-168609.953.2—IBM i is Affected By Remote Code Execution Vulnerability []
CVE-2026-549168.847.4—NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missi…
CVE-2026-729805.545.4—Windows Hello Security Feature Bypass Vulnerability
CVE-2026-321728.045.1—Microsoft Power Apps Remote Code Execution Vulnerability
CVE-2026-542328.844.8—vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile
CVE-2022-362717.841.5——
CVE-2026-78708.840.0—IBM i is Affected by Privilege Escalation []
CVE-2026-550137.138.0—Windows Remote Help Defense Spoofing Vulnerability
CVE-2025-109393.733.0—Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console
CVE-2026-443588.222.4—Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint
CVE-2026-346328.621.5—Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2026-483888.621.1—Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2026-761998.619.9—Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
adobe7
microsoft7
amd4
dell4
acronis3
ibm3
red hat3
amazon2
cisco2
foxit software2
geovision2
mobatek2
nvidia2
abb1
angular1