Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-489
Weakness type CWE-489 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 26 | 25 | 0 |
Monthly trend
▂▁▁▁▁▁▂▃▂▇▅█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 1 · 2026-07 7 · 2026-08 4 · 2026-09 8 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-9133 | 8.3 | 64.1 | — | Arbitrary file read in rabbitmq-aws plugin |
| CVE-2026-40035 | 9.3 | 52.4 | — | Unfurl - Werkzeug Debugger Exposure via String Config Parsing |
| CVE-2026-13313 | 8.9 | 50.8 | — | — |
| CVE-2026-41186 | 6.0 | 50.1 | — | Unauthenticated Go pprof exposure in Calico debug server |
| CVE-2026-59092 | 7.0 | 49.6 | — | JuiceFS - Authentication Bypass via pprof and metrics Endpoints |
| CVE-2026-49188 | 8.7 | 48.3 | — | Elevated Root Command Execution via ai_cmd Sockets |
| CVE-2026-58191 | 6.1 | 44.9 | — | Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes |
| CVE-2026-53952 | 9.8 | 44.3 | — | GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setu… |
| CVE-2026-84486 | 8.2 | 42.4 | — | Automation-controller: automation-controller-container: automation-controller: unauthen… |
| CVE-2026-66405 | 8.7 | 41.3 | — | — |
| CVE-2026-58378 | 8.6 | 36.2 | — | Allwinner TV Box TV98 ADB exposed on network |
| CVE-2026-66403 | 8.7 | 35.3 | — | — |
| CVE-2026-45728 | 7.5 | 33.6 | — | Algernon: Single-file mode unconditionally enables debug mode |
| CVE-2026-54798 | 7.1 | 33.1 | — | — |
| CVE-2026-103475 | 9.3 | 31.6 | — | yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure |
| CVE-2026-77545 | 9.0 | 31.0 | — | — |
| CVE-2026-66787 | 5.4 | 26.8 | — | Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 |
| CVE-2025-4106 | 8.9 | 23.1 | — | WatchGuard Firebox leftover debug code vulnerability |
| CVE-2026-102628 | 9.2 | 18.5 | — | Cadmos LTI exposure of sensitive information via debug mode |
| CVE-2026-65893 | 7.0 | 12.3 | — | Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| acer | 2 |
| ecovacs robotics | 2 |
| red hat | 2 |
| siemens | 2 |
| allwinner | 1 |
| anjvision | 1 |
| appium | 1 |
| asus | 1 |
| aws | 1 |
| cp-plus | 1 |
| dell | 1 |
| eummena | 1 |
| getsimplecms | 1 |
| getsimplecms-ce | 1 |
| insyde software | 1 |