Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-639
Weakness type CWE-639 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1209 | 1201 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▇█▂
2025-11 0 · 2025-12 2 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 53 · 2026-06 164 · 2026-07 243 · 2026-08 329 · 2026-09 383 · 2026-10 28
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55255 | 8.4 | 57.9 | KEV | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attac… |
| CVE-2026-28316 | 9.1 | 81.4 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-8679 | 7.5 | 78.5 | — | AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference t… |
| CVE-2026-89063 | 7.5 | 75.3 | — | Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Refer… |
| CVE-2021-38624 | 6.5 | 73.7 | — | Windows Key Storage Provider Security Feature Bypass Vulnerability |
| CVE-2026-47101 | 8.7 | 70.1 | — | LiteLLM < 1.83.14 Privilege Escalation via API Key Generation |
| CVE-2026-8839 | 5.3 | 69.5 | — | MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Referenc… |
| CVE-2026-100885 | 5.5 | 61.4 | — | Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization |
| CVE-2026-54568 | 4.3 | 60.8 | — | Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to R… |
| CVE-2026-69558 | 8.6 | 60.7 | — | Microsoft Partner Center Information Disclosure Vulnerability |
| CVE-2026-73298 | 8.7 | 60.5 | — | Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/wr… |
| CVE-2026-57205 | 4.3 | 58.6 | — | SimpleChat: Authenticated users can access other users' profile metadata through user I… |
| CVE-2026-46414 | 8.8 | 56.8 | — | Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking |
| CVE-2023-53955 | 9.3 | 56.8 | — | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References |
| CVE-2026-83711 | 10.0 | 55.6 | — | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability |
| CVE-2026-86465 | 6.5 | 55.5 | — | Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via… |
| CVE-2026-73841 | 8.8 | 55.4 | — | OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo open… |
| CVE-2026-69865 | 10.0 | 55.0 | — | Microsoft Container Registry Elevation of Privilege Vulnerability |
| CVE-2026-28302 | 9.1 | 54.6 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28305 | 9.1 | 54.6 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 24 |
| apache | 19 |
| ibm | 14 |
| microsoft | 14 |
| misp | 14 |
| flowiseai | 13 |
| n8n-io | 12 |
| roskus | 12 |
| grokability | 11 |
| concrete cms | 10 |
| mervinpraison | 10 |
| open-webui | 10 |
| elastic | 9 |
| baptistearno | 8 |
| coollabsio | 8 |