Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-601
Weakness type CWE-601 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 296 | 286 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▅▇▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 3 · 2026-05 15 · 2026-06 58 · 2026-07 84 · 2026-08 52 · 2026-09 67 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-38000 | 6.1 | 91.9 | KEV | Google Chromium Intents |
| CVE-2012-0518 | 4.7 | 91.5 | KEV | Oracle Fusion Middleware |
| CVE-2024-8883 | 6.1 | 81.2 | — | Keycloak: vulnerable redirect uri validation results in open redirec |
| CVE-2020-1059 | 4.3 | 80.7 | — | Microsoft Edge Spoofing Vulnerability |
| CVE-2023-6927 | 6.1 | 64.7 | — | Keycloak: open redirect via "form_post.jwt" jarm response mode |
| CVE-2023-6291 | 7.1 | 59.9 | — | Keycloak: redirect_uri validation bypass |
| CVE-2026-40961 | 7.2 | 53.7 | — | Apache Airflow: Open Redirect Bypass Vulnerability |
| CVE-2026-47645 | 8.8 | 53.6 | — | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability |
| CVE-2026-33102 | 9.3 | 52.2 | — | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-41106 | 9.3 | 52.2 | — | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-14902 | 6.1 | 51.7 | — | — |
| CVE-2026-53437 | 4.3 | 50.8 | — | — |
| CVE-2025-14524 | 5.3 | 50.0 | — | bearer token leak on cross-protocol redirect |
| CVE-2026-67178 | 7.8 | 50.0 | — | Open Redirect in MISP Installer-Generated Apache Configuration |
| CVE-2026-51564 | 4.9 | 49.6 | — | — |
| CVE-2026-53573 | 4.8 | 49.3 | — | core-geonetwork has an Open Redirect Bypass |
| CVE-2026-48895 | 2.1 | 49.2 | — | Apache APISIX: Cas-auth Host header influence on CAS service URL |
| CVE-2026-44915 | 2.1 | 49.0 | — | Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value |
| CVE-2024-43543 | 6.8 | 48.2 | — | Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
| CVE-2024-43536 | 6.8 | 48.0 | — | Windows Mobile Broadband Driver Remote Code Execution Vulnerability |