Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-610
Weakness type CWE-610 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 19 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇██▅▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 5 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-27593 | 10.0 | 99.8 | KEV | DeadBolt Ransomware |
| CVE-2026-57301 | 8.8 | 48.2 | — | — |
| CVE-2026-34327 | 8.2 | 47.0 | — | Microsoft Partner Center Spoofing Vulnerability |
| CVE-2026-10816 | 7.1 | 45.7 | — | Arbitrary File Read (Unauthenticated) |
| CVE-2026-55389 | 7.5 | 43.9 | — | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref`… |
| CVE-2026-55390 | 7.5 | 42.8 | — | Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path trav… |
| CVE-2026-15583 | 8.6 | 42.7 | — | SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header |
| CVE-2026-19032 | 5.3 | 42.7 | — | jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.f… |
| CVE-2026-62960 | 7.4 | 37.4 | — | Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UN… |
| CVE-2026-76572 | 5.1 | 37.2 | — | pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference |
| CVE-2026-79256 | 8.3 | 36.1 | — | — |
| CVE-2026-12788 | 2.1 | 31.9 | — | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml … |
| CVE-2026-45760 | 8.1 | 30.3 | — | Apache Camel K: Camel K Cross-Namespace Build Deputy Attack |
| CVE-2026-68562 | 6.2 | 29.5 | — | Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosur… |
| CVE-2026-78966 | 4.3 | 23.6 | — | — |
| CVE-2026-81375 | 8.3 | 22.3 | — | Confused Deputy in Application Integration allows Internal File Read |
| CVE-2026-12879 | 5.9 | 20.6 | — | Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy |
| CVE-2026-0418 | 4.3 | 14.2 | — | Certain NETGEAR devices allow administrators to tamper with system |
| CVE-2026-95376 | 8.0 | 9.0 | — | — |
| CVE-2026-21810 | 4.4 | 0.1 | — | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 3 | |
| google cloud | 2 |
| koxudaxi | 2 |
| apache | 1 |
| fasterxml | 1 |
| git-for-windows | 1 |
| grafana | 1 |
| hclsoftware | 1 |
| jenkins project | 1 |
| microsoft | 1 |
| netgear | 1 |
| netscaler | 1 |
| pkp | 1 |
| qnap systems | 1 |
| red hat | 1 |