Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-497
Weakness type CWE-497 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 93 | 88 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▆█▅▇▁
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 19 · 2026-07 28 · 2026-08 14 · 2026-09 23 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-31955 | 5.5 | 99.6 | KEV | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-13999 | 7.3 | 78.8 | — | Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure |
| CVE-2025-34283 | 7.1 | 62.8 | — | Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes |
| CVE-2026-71330 | 7.5 | 62.4 | — | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
| CVE-2024-13998 | 6.0 | 60.6 | — | Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure |
| CVE-2026-69723 | 5.7 | 58.1 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-14808 | 9.3 | 51.1 | — | PROG MIS|Prog Management System - Exposure of Sensitive Information |
| CVE-2026-56124 | 8.7 | 48.7 | — | phpUploader < 2.0.2 Unauthenticated Database Exposure via index model |
| CVE-2018-25358 | 8.7 | 46.1 | — | D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi |
| CVE-2025-46421 | 6.8 | 45.4 | — | Libsoup: information disclosure may leads libsoup client sends authorization header to … |
| CVE-2026-44945 | 9.1 | 44.7 | — | Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
| CVE-2026-27553 | 6.5 | 44.7 | — | Information Disclosure via Schema Path Manipulation |
| CVE-2026-81387 | 5.5 | 44.2 | — | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81394 | 5.5 | 44.2 | — | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-75928 | 6.9 | 43.0 | — | Brushfire unauthenticated information disclosure |
| CVE-2026-69127 | 6.9 | 41.1 | — | Kirby: System path exposure from error messages in the REST API |
| CVE-2026-50294 | 6.2 | 41.1 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-41928 | 6.9 | 40.7 | — | Vvveb < 1.0.8.2 Information Disclosure via Cron Controller |
| CVE-2026-68842 | 5.5 | 39.1 | — | Windows MIDI Service Module Information Disclosure Vulnerability |
| CVE-2026-69315 | 5.5 | 39.1 | — | Windows License Manager Information Disclosure Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 11 |
| red hat | 4 |
| sap_se | 4 |
| crocoblock | 3 |
| nagios | 3 |
| passmark software | 2 |
| pronetiqs | 2 |
| ads wpquads | 1 |
| amd | 1 |
| asus | 1 |
| bdthemes | 1 |
| bookingwp | 1 |
| bootstrapped ventures | 1 |
| brushfire | 1 |
| byteflows | 1 |