boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-427

Weakness type CWE-427 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
73652

Monthly trend

▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▃█▅▇

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 6 · 2026-06 23 · 2026-07 14 · 2026-08 20

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-31536.597.9KEVCisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
CVE-2020-34337.895.2KEVCisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
CVE-2025-298027.357.1Visual Studio Elevation of Privilege Vulnerability
CVE-2025-298175.754.6Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2025-298037.351.0Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Priv…
CVE-2026-542328.844.3vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile
CVE-2026-168609.941.5IBM i is Affected By Remote Code Execution Vulnerability []
CVE-2022-362717.840.6
CVE-2025-109393.731.3Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console
CVE-2026-78708.827.4IBM i is Affected by Privilege Escalation []
CVE-2026-321728.026.5Microsoft Power Apps Remote Code Execution Vulnerability
CVE-2026-346328.619.7Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2025-300338.510.9
CVE-2026-187187.111.0Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
CVE-2025-416708.79.0Untrusted Search Path
CVE-2026-443588.28.0Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint
CVE-2026-389727.88.0
CVE-2026-66457.37.7Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows
CVE-2026-483888.67.0Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2026-572397.86.7Foxit PDF Editor/Reader Local Privilege Escalation

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
adobe6
amd4
microsoft4
acronis3
dell3
amazon2
cisco2
ibm2
mobatek2
red hat2
abb1
angular1
anssi1
arksigner software and hardware industry and trade1
checkmal1