Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-61
Weakness type CWE-61 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 45 | 45 | 1 |
Monthly trend
▂▂█▆▆▆▁
2026-04 1 · 2026-05 2 · 2026-06 13 · 2026-07 10 · 2026-08 10 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-54420 | 8.5 | 55.3 | KEV | LiteSpeed cPanel Plugin |
| CVE-2026-91099 | 5.1 | 61.0 | — | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-56748 | 8.7 | 58.9 | — | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import |
| CVE-2026-63125 | 9.9 | 50.0 | — | Incus vulnerable to root RCE via image backup.yaml symlink |
| CVE-2026-55447 | 9.6 | 49.9 | — | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit |
| CVE-2026-41937 | 8.6 | 48.3 | — | Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload |
| CVE-2026-55168 | 6.5 | 47.3 | — | Runtipi: Authenticated arbitrary file write via backup restore symlink planting |
| CVE-2026-49248 | 8.3 | 45.3 | — | OneDev: RCE through absolute-path symlink following allows low-privileged users to over… |
| CVE-2026-62992 | 6.9 | 43.0 | — | Smarty: Symlink path traversal out of trusted directories |
| CVE-2026-56876 | 8.6 | 42.5 | — | extract-zip unvalidated symlink path traversal |
| CVE-2026-52811 | 9.0 | 38.8 | — | Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym |
| CVE-2026-57825 | 5.7 | 38.7 | — | — |
| CVE-2026-17459 | 2.1 | 38.3 | — | perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink |
| CVE-2026-5223 | 6.5 | 33.6 | — | Crates in third party registries can override the cached source of other crates |
| CVE-2026-55686 | 5.3 | 32.2 | — | Podman: WORKDIR symlink traversal vulnerability |
| CVE-2026-41326 | 8.2 | 28.8 | — | Kata Containers: CopyFile Policy Subversion via Symlinks |
| CVE-2026-97024 | 7.1 | 21.6 | — | Flatpak: flatpak: arbitrary write in root context via path traversal in deploy director… |
| CVE-2026-97023 | 7.1 | 18.8 | — | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy … |
| CVE-2026-13201 | 7.3 | 18.1 | — | Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enab… |
| CVE-2026-53802 | 8.4 | 13.5 | — | rsync < 3.5.0 Arbitrary File Read via Symlink Following |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 7 |
| flatpak | 3 |
| dell | 2 |
| amazon web services | 1 |
| apple | 1 |
| containerd | 1 |
| containers | 1 |
| cribl | 1 |
| givanz | 1 |
| go standard library | 1 |
| gogs | 1 |
| hp | 1 |
| huggingface | 1 |
| ilya-zlobintsev | 1 |
| kata-containers | 1 |