Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-551
Weakness type CWE-551 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 13 | 0 |
Monthly trend
▅▁▆█▁▅▅▁
2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 4 · 2026-07 0 · 2026-08 2 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33186 | 9.1 | 75.3 | — | gRPC-Go has an authorization bypass via missing leading slash in :path |
| CVE-2026-44573 | 7.5 | 53.8 | — | Next.js: Middleware / Proxy bypass in Pages Router applications using i18n |
| CVE-2026-44575 | 7.5 | 53.8 | — | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes |
| CVE-2026-44574 | 8.1 | 50.1 | — | Next.js: Middleware / Proxy bypass through dynamic route parameter injection |
| CVE-2026-50559 | 7.5 | 50.1 | — | Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities |
| CVE-2016-20030 | 9.3 | 44.8 | — | ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction |
| CVE-2026-87743 | 7.5 | 42.3 | — | Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus … |
| CVE-2026-45832 | 8.8 | 42.1 | — | — |
| CVE-2026-13676 | 7.5 | 39.3 | — | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| CVE-2026-89060 | 7.7 | 38.9 | — | Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multi… |
| CVE-2026-15573 | 8.1 | 37.6 | — | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matchin… |
| CVE-2026-16102 | 8.1 | 37.6 | — | Keycloak-services: keycloak-services: default dcr policy allows role forgery via user p… |
| CVE-2026-57920 | 7.7 | 29.4 | — | — |