Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-524
Weakness type CWE-524 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 37 | 37 | 0 |
Monthly trend
▂▂█▇▄▅▄
2026-04 1 · 2026-05 1 · 2026-06 11 · 2026-07 9 · 2026-08 5 · 2026-09 6 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-25703 | 7.3 | 55.2 | — | Potential information leakage from manager /network/graph API in NeuVector |
| CVE-2026-35172 | 7.5 | 50.2 | — | Distribution has stale blob access resurrection via repo-scoped redis descriptor cache … |
| CVE-2026-82755 | 6.3 | 49.8 | — | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cach… |
| CVE-2026-13007 | 8.7 | 47.4 | — | Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure |
| CVE-2026-93748 | 8.7 | 42.9 | — | http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale |
| CVE-2026-89186 | 6.3 | 42.4 | — | mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letti… |
| CVE-2026-71316 | 7.5 | 41.1 | — | Nuxt runtime payload cache discloses another user's SSR data across users and to unauth… |
| CVE-2026-61836 | 8.6 | 38.8 | — | Directus: Authorization-dependent response served from unsegmented cache key |
| CVE-2026-40012 | 5.3 | 37.1 | — | Information about ECS zero scoped answers might leak to clients that use a specific ECS |
| CVE-2026-53943 | 9.6 | 36.6 | — | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header |
| CVE-2026-35193 | 2.3 | 35.3 | — | Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddle… |
| CVE-2026-48588 | 2.3 | 34.9 | — | Potential exposure of private data via cached Set-Cookie response |
| CVE-2026-50170 | 8.2 | 34.6 | — | Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferC… |
| CVE-2026-64792 | 7.5 | 34.4 | — | Joomla Extension - regularlabs.com - disclosure of restricted content via search index … |
| CVE-2026-9678 | 5.9 | 34.0 | — | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass |
| CVE-2026-48901 | 7.5 | 33.6 | — | Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects |
| CVE-2026-65755 | 7.5 | 33.6 | — | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Any… |
| CVE-2026-14643 | 7.5 | 31.4 | — | undici vulnerable to cross-user information disclosure via whitespace around equals in … |
| CVE-2026-47225 | 6.0 | 29.9 | — | Improper Search Cache Isolation for Scoped Search API Keys in Typesense |
| CVE-2026-59213 | 5.0 | 28.9 | — | Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aioc… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| vercel | 5 |
| angular | 4 |
| undici | 3 |
| djangoproject | 2 |
| regularlabs.com | 2 |
| api-platform | 1 |
| ash-project | 1 |
| directus | 1 |
| distribution | 1 |
| django-cms | 1 |
| 1 | |
| joomla! project | 1 |
| kornelski | 1 |
| linux | 1 |
| netty | 1 |