Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-441
Weakness type CWE-441 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 93 | 92 | 1 |
Monthly trend
▁▁▁▁▁▁▂▃▃█▁
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 3 · 2026-05 1 · 2026-06 8 · 2026-07 15 · 2026-08 12 · 2026-09 50 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-83548 | 10.0 | 95.0 | KEV | — |
| CVE-2025-62718 | 6.3 | 66.8 | — | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| CVE-2026-44494 | 8.7 | 59.3 | — | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-23751 | 9.3 | 57.8 | — | Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting |
| CVE-2026-72526 | 9.9 | 51.7 | — | Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub ten… |
| CVE-2026-49086 | 6.5 | 50.8 | — | Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and to… |
| CVE-2026-63643 | 6.3 | 50.0 | — | MagicMirror: ssrf calendar .js |
| CVE-2026-46592 | 7.5 | 48.1 | — | Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed n… |
| CVE-2026-67567 | 9.9 | 47.9 | — | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart… |
| CVE-2026-100706 | 9.4 | 47.5 | — | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath |
| CVE-2026-54628 | 8.6 | 46.6 | — | Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modu… |
| CVE-2026-42043 | 10.0 | 45.7 | — | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo… |
| CVE-2026-17107 | 8.5 | 45.1 | — | Cluster-proxy: impersonation-header injection grants cluster-admin on every managed clu… |
| CVE-2026-44945 | 9.1 | 44.7 | — | Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
| CVE-2026-70398 | 9.6 | 42.2 | — | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonam… |
| CVE-2026-42933 | 10.0 | 41.6 | — | Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs |
| CVE-2026-86600 | 8.2 | 41.5 | — | Workload identity attestation generated before login host validation in Snowflake drivers |
| CVE-2026-56675 | 8.3 | 40.8 | — | 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs |
| CVE-2026-86115 | 5.3 | 40.7 | — | Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a Use… |
| CVE-2026-61793 | 6.9 | 40.4 | — | Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 33 | |
| red hat | 9 |
| axios | 5 |
| apache | 2 |
| better-auth | 2 |
| elastic | 2 |
| microsoft | 2 |
| snowflake | 2 |
| sooperset | 2 |
| @better-auth | 1 |
| @capacitor | 1 |
| @fastify/reply-from | 1 |
| acacode | 1 |
| angular | 1 |
| appium | 1 |