Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-522
Weakness type CWE-522 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 187 | 180 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▇█▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 1 · 2026-04 1 · 2026-05 11 · 2026-06 22 · 2026-07 35 · 2026-08 47 · 2026-09 57 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-29583 | 9.8 | 99.8 | KEV | Zyxel Multiple Products |
| CVE-2021-30116 | 9.8 | 99.7 | KEV | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6 |
| CVE-2017-9248 | 9.8 | 99.5 | KEV | Progress ASP.NET AJAX and Sitefinity |
| CVE-2014-1812 | 8.8 | 99.2 | KEV | Microsoft Windows |
| CVE-2021-22681 | 9.8 | 99.2 | KEV | Rockwell Multiple Products |
| CVE-2021-42306 | 8.1 | 88.0 | — | Azure Active Directory Information Disclosure Vulnerability |
| CVE-2026-32315 | 5.5 | 86.7 | — | motionEye: World-Readable Configuration File Exposes Admin Password Hash |
| CVE-2026-57219 | 8.7 | 86.2 | — | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoi… |
| CVE-2025-26628 | 7.3 | 70.7 | — | Azure Local Cluster Information Disclosure Vulnerability |
| CVE-2026-62839 | 6.5 | 58.6 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-81381 | 7.5 | 57.5 | — | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-47282 | 6.5 | 57.5 | — | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-64918 | 6.5 | 57.5 | — | Microsoft Office Spoofing Vulnerability |
| CVE-2026-48295 | 7.5 | 56.2 | — | CAI Content Credentials | Insufficiently Protected Credentials (CWE-522) |
| CVE-2026-32171 | 8.8 | 54.3 | — | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-6253 | 5.9 | 53.4 | — | proxy credentials leak over redirect-to proxy |
| CVE-2026-61516 | 9.3 | 51.9 | — | Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint |
| CVE-2026-61802 | 6.5 | 51.6 | — | Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local… |
| CVE-2026-54617 | 9.8 | 50.6 | — | GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler |
| CVE-2026-62882 | 4.3 | 50.1 | — | Microsoft Outlook Spoofing Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 10 |
| ibm | 6 |
| apache | 5 |
| curl | 5 |
| mariadb-corporation | 5 |
| netcore | 5 |
| openclaw | 5 |
| asynchttpclient | 3 |
| flytohub | 3 |
| getgrav | 3 |
| gitlab | 3 |
| schneider electric | 3 |
| siyuan-note | 3 |
| aehrc | 2 |
| cisco | 2 |