Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-636
Weakness type CWE-636 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 37 | 36 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▄█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 4 · 2026-07 6 · 2026-08 6 · 2026-09 16 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43532 | 8.8 | 96.0 | — | Remote Registry Service Elevation of Privilege Vulnerability |
| CVE-2026-53913 | 9.8 | 64.1 | — | Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins… |
| CVE-2026-68746 | 7.7 | 55.1 | — | Livebook Teams identity check fails open when the deployment group is unresolvable, all… |
| CVE-2026-53459 | 9.3 | 53.8 | — | Bambuddy's authentication fails open on database errors, allowing unauthenticated acces… |
| CVE-2026-73421 | 9.1 | 49.0 | — | NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (a… |
| CVE-2026-77560 | 8.1 | 47.5 | — | Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insens… |
| CVE-2026-50528 | 8.2 | 47.4 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-69306 | 8.2 | 43.6 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-81379 | 8.2 | 43.6 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-95676 | 7.4 | 40.5 | — | AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authenticati… |
| CVE-2026-77866 | 9.0 | 39.3 | — | SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts |
| CVE-2026-70452 | 9.1 | 37.9 | — | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
| CVE-2026-44094 | 8.3 | 37.1 | — | Fallback to second RAUC slot with default credentials |
| CVE-2026-46482 | 5.3 | 36.7 | — | MyBB: Security Question insufficient validation |
| CVE-2026-54762 | 5.9 | 35.5 | — | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails |
| CVE-2026-95848 | 9.3 | 34.5 | — | Moquette fails open when configured authentication or authorization classes cannot load |
| CVE-2026-92591 | 8.2 | 32.6 | — | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2026-61595 | 7.7 | 30.2 | — | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other te… |
| CVE-2026-18329 | 8.8 | 29.3 | — | NGINX ngx_http_js_module vulnerability |
| CVE-2026-86120 | 5.3 | 28.2 | — | APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permissio… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 4 |
| indian motorcycle | 2 |
| openclaw | 2 |
| apache | 1 |
| apitable | 1 |
| ash-project | 1 |
| bytebase | 1 |
| chewkeanho | 1 |
| craftcms | 1 |
| djust-org | 1 |
| f5 | 1 |
| getgrav | 1 |
| guzzle | 1 |
| heymrun | 1 |
| igel | 1 |