Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-428
Weakness type CWE-428 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 40 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▁▁▂█▁▂▂▁
2025-11 0 · 2025-12 2 · 2026-01 6 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 23 · 2026-07 1 · 2026-08 2 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-15358 | 7.5 | 64.5 | — | Path Traversal Vulnerability |
| CVE-2024-43457 | 7.8 | 47.8 | — | Windows Setup and Deployment Elevation of Privilege Vulnerability |
| CVE-2024-58288 | 8.7 | 30.2 | — | Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation |
| CVE-2021-47767 | 8.5 | 13.8 | — | 10-Strike Network Inventory Explorer Pro 9.31 - 'srvInventoryWebServer' Unquoted Servic… |
| CVE-2021-47806 | 8.5 | 13.8 | — | Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path |
| CVE-2021-47792 | 8.5 | 12.7 | — | Remote Mouse 4.002 - Unquoted Service Path |
| CVE-2021-47807 | 8.5 | 12.7 | — | Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path |
| CVE-2024-58315 | 8.5 | 12.6 | — | Tosibox Key Service 3.3.0 Local Privilege Escalation via Unquoted Service Path |
| CVE-2022-50971 | 8.5 | 12.0 | — | Malwarebytes 4.5 Unquoted Service Path Privilege Escalation |
| CVE-2020-37100 | 8.5 | 11.1 | — | Sync Breeze Enterprise 12.4.18 - Unquoted Service Path |
| CVE-2026-25865 | 8.5 | 8.8 | — | Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec |
| CVE-2026-66839 | 8.4 | 8.8 | — | — |
| CVE-2016-20094 | 8.5 | 8.6 | — | AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege |
| CVE-2026-81469 | 7.8 | 8.0 | — | — |
| CVE-2026-18755 | 7.3 | 7.7 | — | GV-ASManager DLL hijacking vulnerability |
| CVE-2025-71326 | 8.5 | 7.2 | — | AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation |
| CVE-2019-25285 | 8.5 | 7.0 | — | Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service… |
| CVE-2020-36987 | 8.5 | 6.6 | — | Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path |
| CVE-2016-20087 | 8.5 | 6.4 | — | Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege |
| CVE-2016-20088 | 8.5 | 6.4 | — | Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation |