Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-532
Weakness type CWE-532 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 168 | 159 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▄▆█▂
2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 1 · 2026-03 2 · 2026-04 5 · 2026-05 14 · 2026-06 19 · 2026-07 22 · 2026-08 37 · 2026-09 53 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-21492 | 4.4 | 84.5 | KEV | Samsung Mobile Devices |
| CVE-2025-24984 | 4.6 | 79.6 | KEV | Windows NTFS Information Disclosure Vulnerability |
| CVE-2025-25002 | 6.8 | 65.0 | — | Azure Local Cluster Information Disclosure Vulnerability |
| CVE-2026-54236 | 5.3 | 59.2 | — | vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router |
| CVE-2026-64800 | 5.7 | 56.6 | — | — |
| CVE-2026-20818 | 6.2 | 52.6 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-19363 | 5.5 | 50.2 | — | lmammino oidc-authorizer Lambda Authorizer handler.rs log file |
| CVE-2026-92918 | 8.7 | 49.3 | — | admin3 through 3.0.0 Session Token Disclosure via Audit Log |
| CVE-2026-68969 | 6.5 | 49.0 | — | Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audi… |
| CVE-2026-65945 | 6.5 | 48.7 | — | Apache Ranger: Logs contain replayable JWT bearer tokens |
| CVE-2026-12053 | 7.5 | 48.2 | — | Insertion of Sensitive Information into Log File in GitLab |
| CVE-2026-49200 | 10.0 | 47.6 | — | Acer Wave 7 router: Broken Access Control |
| CVE-2026-21222 | 5.5 | 47.1 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-66780 | 6.5 | 45.7 | — | Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace … |
| CVE-2026-14948 | 8.7 | 45.3 | — | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensiti… |
| CVE-2026-85171 | 7.1 | 44.9 | — | n8n before 1.123.73 Credential Exposure via Error Logging |
| CVE-2026-41184 | 6.0 | 42.6 | — | ServiceAccount token disclosure via install-cni container logs |
| CVE-2024-9621 | 5.3 | 42.3 | — | Io.quarkiverse.cxf:quarkus-cxf: quarkus cxf may log user password and secret to applica… |
| CVE-2024-31245 | 7.5 | 42.2 | — | WordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerability |
| CVE-2024-31249 | 7.5 | 41.4 | — | WordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vul… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 12 |
| red hat | 10 |
| dell | 9 |
| microsoft | 9 |
| apache | 7 |
| mongodb | 7 |
| apple | 6 |
| arista networks | 5 |
| brocade | 5 |
| hclsoftware | 5 |
| open-telemetry | 4 |
| spring | 4 |
| jahlives | 3 |
| jetbrains | 3 |
| renovatebot | 3 |