Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-451
Weakness type CWE-451 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 219 | 213 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▅▂▄▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 2 · 2026-05 6 · 2026-06 94 · 2026-07 47 · 2026-08 19 · 2026-09 42 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-38112 | 7.5 | 99.7 | KEV | Windows MSHTML Platform Spoofing Vulnerability |
| CVE-2024-43461 | 8.8 | 99.0 | KEV | Windows MSHTML Platform Spoofing Vulnerability |
| CVE-2026-21527 | 6.5 | 94.7 | — | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-33118 | 4.3 | 51.7 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-35429 | 4.3 | 51.7 | — | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-45650 | 4.3 | 51.7 | — | Microsoft Bing Search Spoofing Vulnerability |
| CVE-2026-0391 | 6.5 | 48.9 | — | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2025-29796 | 4.7 | 46.2 | — | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2026-64735 | 6.5 | 43.8 | — | — |
| CVE-2024-38082 | 4.7 | 40.4 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-38093 | 4.3 | 40.4 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-40416 | 4.3 | 40.2 | — | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-64730 | 6.5 | 39.6 | — | — |
| CVE-2026-42891 | 6.5 | 38.6 | — | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-45150 | 6.3 | 34.8 | — | Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing |
| CVE-2026-53829 | 8.5 | 34.1 | — | OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display |
| CVE-2026-33119 | 5.4 | 33.3 | — | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
| CVE-2026-9106 | 4.8 | 28.0 | — | UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized org… |
| CVE-2026-45488 | 5.9 | 27.8 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-18487 | 5.4 | 24.9 | — | Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 176 | |
| microsoft | 14 |
| mozilla | 10 |
| apple | 2 |
| symfony | 2 |
| the browser company of new york | 2 |
| dropbox(hellosign) | 1 |
| dräger | 1 |
| f5 | 1 |
| foxit software | 1 |
| github | 1 |
| gnome | 1 |
| hcl software | 1 |
| mathworks | 1 |
| openclaw | 1 |