Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-470
Weakness type CWE-470 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 61 | 60 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 7 · 2026-07 14 · 2026-08 14 · 2026-09 24 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-21985 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2026-82078 | 9.4 | 99.1 | KEV | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector |
| CVE-2026-65608 | 8.7 | 69.0 | — | Grav before 2.0.9 Remote Code Execution via FlexDirectory |
| CVE-2026-42027 | 9.8 | 68.8 | — | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader |
| CVE-2026-44416 | 9.8 | 68.2 | — | Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation |
| CVE-2026-86792 | 8.8 | 66.9 | — | Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Sc… |
| CVE-2026-58400 | 9.1 | 66.8 | — | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configur… |
| CVE-2026-62379 | 9.8 | 63.6 | — | OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createC… |
| CVE-2026-44795 | 8.8 | 61.9 | — | Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types |
| CVE-2026-46562 | 9.8 | 60.8 | — | Yamcs: Remote Code Execution via Mission Database algorithm override |
| CVE-2026-63317 | 5.6 | 56.8 | — | Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descripto… |
| CVE-2026-55107 | 10.0 | 55.0 | — | Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → p… |
| CVE-2026-55559 | 9.8 | 54.5 | — | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInsta… |
| CVE-2026-6020 | 7.2 | 54.4 | — | ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via '… |
| CVE-2026-17593 | 7.2 | 54.2 | — | Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration |
| CVE-2026-41871 | 9.8 | 53.2 | — | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch RES… |
| CVE-2026-46718 | 6.5 | 51.0 | — | Apache Calcite: A user-controled model can load arbitrary classes, leading to code exec… |
| CVE-2026-13181 | 8.1 | 50.6 | — | RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.… |
| CVE-2026-41870 | 8.8 | 50.1 | — | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch S… |
| CVE-2026-79987 | 8.7 | 49.3 | — | Low-privilege RCE through element-search eager loading |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 9 |
| ibm | 4 |
| jenkins project | 2 |
| messagepack-csharp | 2 |
| mongodb | 2 |
| progress | 2 |
| red hat | 2 |
| statamic | 2 |
| yamcs | 2 |
| aws | 1 |
| cakephp | 1 |
| craftcms | 1 |
| dell | 1 |
| devitemsllc | 1 |
| djust-org | 1 |