Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-668
Weakness type CWE-668 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 55 | 45 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▂▂▁▁▂▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▂▁▃▆▇▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 8 · 2026-07 10 · 2026-08 10 · 2026-09 12 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21626 | 8.6 | 97.2 | — | runc container breakout through process.cwd trickery and leaked fds |
| CVE-2026-44008 | 9.8 | 58.3 | — | vm2: Snabox breakout via `neutralizeArraySpeciesBatch` |
| CVE-2026-45411 | 9.8 | 58.3 | — | vm2: Sandbox Breakout Using Async Generator |
| CVE-2026-72764 | 5.8 | 55.5 | — | n8n before 1.123.67 Module Cache Poisoning via Code Node |
| CVE-2026-42535 | 9.1 | 51.9 | — | Apache HTTP Server: mod_dav_fs protected directory access |
| CVE-2026-44009 | 9.8 | 51.9 | — | vm2: Sandbox Breakout Through Null Proto Exception |
| CVE-2026-45077 | 8.3 | 50.1 | — | Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener |
| CVE-2023-21714 | 5.5 | 46.7 | — | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-67427 | 8.6 | 46.4 | — | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denyli… |
| CVE-2026-54504 | 8.8 | 45.4 | — | MCP Documentation Server: Web UI API binds to all interfaces without authentication by … |
| CVE-2026-54582 | 6.0 | 44.3 | — | mport package installation can overwrite existing unmanaged or differently owned files |
| CVE-2026-47141 | 6.9 | 41.1 | — | vm2: NodeVM observability builtins leak host process and HTTP request data |
| CVE-2026-73843 | 9.6 | 39.4 | — | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gate… |
| CVE-2026-92940 | 10.0 | 38.8 | — | vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent |
| CVE-2026-50202 | 5.9 | 38.8 | — | Steeltoe's static JWKS cache shared across schemes and never invalidated |
| CVE-2023-21687 | 5.5 | 38.0 | — | HTTP.sys Information Disclosure Vulnerability |
| CVE-2026-14960 | 9.8 | 37.6 | — | CVE-2026-14960 |
| CVE-2026-56077 | 7.1 | 36.5 | — | PraisonAI - Information Disclosure via Shared MultiAgentLedger State |
| CVE-2026-57231 | 7.5 | 35.8 | — | Podman: Malformed Image can trick podman run into leaking host environment variables in… |
| CVE-2026-14611 | 5.3 | 35.0 | — | DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of r… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 6 |
| patriksimek | 5 |
| 4 | |
| microsoft | 2 |
| siyuan-note | 2 |
| acer | 1 |
| activepieces | 1 |
| andrea9293 | 1 |
| apache | 1 |
| cli | 1 |
| craftcms | 1 |
| darkreader | 1 |
| deepmyst | 1 |
| djust-org | 1 |
| dräger | 1 |