Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-552
Weakness type CWE-552 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 63 | 53 | 4 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▃▃██▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 9 · 2026-06 5 · 2026-07 5 · 2026-08 17 · 2026-09 16 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-17519 | 9.1 | 99.9 | KEV | Apache Flink directory traversal attack: reading remote files through the REST API |
| CVE-2025-11371 | 7.5 | 99.8 | KEV | Gladinet CentreStack and TrioFox Local File Inclusion Flaw |
| CVE-2016-3715 | 5.5 | 99.5 | KEV | ImageMagick ImageMagick |
| CVE-2017-16651 | 7.8 | 98.8 | KEV | Roundcube Roundcube Webmail |
| CVE-2023-36664 | 7.8 | 90.2 | — | — |
| CVE-2021-29024 | 7.5 | 75.6 | — | — |
| CVE-2024-21403 | 9.0 | 70.3 | — | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulner… |
| CVE-2025-66389 | 7.5 | 66.5 | — | — |
| CVE-2026-54629 | 7.5 | 60.4 | — | Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server… |
| CVE-2026-57990 | 7.4 | 59.0 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-11841 | 9.4 | 56.9 | — | CVE-2026-11841 |
| CVE-2026-40624 | 9.3 | 56.2 | — | AVer PTC cameras Files or Directories Accessible to External Parties |
| CVE-2026-73653 | 9.4 | 54.7 | — | Vitest: Browser Mode provider commands bypass the file-access permission gate |
| CVE-2025-0620 | 4.9 | 53.2 | — | Samba: smbd doesn't pick up group membership changes when re-authenticating an expired … |
| CVE-2026-45721 | 9.0 | 53.1 | — | Algernon: handler.lua discovery walks parent directories above the server root |
| CVE-2026-63490 | 7.5 | 51.0 | — | Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix … |
| CVE-2026-63040 | 8.1 | 49.1 | — | Apache InLong: Missing authorization in StreamSource forceDelete |
| CVE-2026-63042 | 8.1 | 49.1 | — | Apache InLong: Missing authorization on DataNode management endpoints |
| CVE-2026-73705 | 8.8 | 47.7 | — | Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fab… |
| CVE-2026-40425 | 6.9 | 47.0 | — | MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Pa… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 5 |
| microsoft | 5 |
| hewlett packard enterprise (hpe) | 3 |
| ibm | 3 |
| grafana | 2 |
| sourcecodester | 2 |
| abb | 1 |
| agentejo | 1 |
| alexta69 | 1 |
| aver | 1 |
| brain trust | 1 |
| code-projects | 1 |
| configserver | 1 |
| danelec | 1 |
| gladinet | 1 |