Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-538
Weakness type CWE-538 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 18 | 0 |
Monthly trend
▂▁▂█▂▄▅▁
2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 1 · 2026-08 3 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-69507 | 5.7 | 58.2 | — | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-49298 | 8.8 | 55.6 | — | Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments |
| CVE-2016-20024 | 9.3 | 53.0 | — | ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation |
| CVE-2026-19229 | 5.5 | 44.9 | — | SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information… |
| CVE-2026-46617 | 8.7 | 39.4 | — | Fission runtime pods automount the fission-fetcher service-account token into the user … |
| CVE-2026-50565 | 4.9 | 36.6 | — | Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-su… |
| CVE-2026-15574 | 7.5 | 36.1 | — | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full cha… |
| CVE-2026-12762 | 5.3 | 32.3 | — | Insertion of Sensitive Information into Externally-Accessible File in IBM Business Auto… |
| CVE-2026-5434 | 5.9 | 24.3 | — | Improper storage of sensitive information |
| CVE-2026-10254 | 5.5 | 23.9 | — | SourceCodester Pet Grooming Management Software admin file information disclosure |
| CVE-2025-36372 | 6.5 | 21.1 | — | IBM® Db2® could disclose sensitive information to an authenticated user from the monito… |
| CVE-2026-29114 | 2.3 | 17.7 | — | — |
| CVE-2026-50099 | 5.1 | 10.9 | — | Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file… |
| CVE-2026-67361 | 6.9 | 10.8 | — | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory … |
| CVE-2019-25717 | 5.3 | 9.4 | — | Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure |
| CVE-2026-57442 | 6.9 | 8.1 | — | MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied a… |
| CVE-2026-25827 | 2.3 | 4.2 | — | — |
| CVE-2026-80175 | 3.3 | 2.6 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| fission | 2 |
| ibm | 2 |
| sourcecodester | 2 |
| apache | 1 |
| bitbonsai | 1 |
| dahua | 1 |
| dell | 1 |
| dräger | 1 |
| honeywell international | 1 |
| j2commerce.com | 1 |
| microsoft | 1 |
| naxclow | 1 |
| red hat | 1 |
| zkteco | 1 |