Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-693
Weakness type CWE-693 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 411 | 386 | 14 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆▆▄█▁
2025-11 0 · 2025-12 2 · 2026-01 3 · 2026-02 2 · 2026-03 5 · 2026-04 3 · 2026-05 13 · 2026-06 90 · 2026-07 82 · 2026-08 60 · 2026-09 127 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21412 | 8.1 | 99.9 | KEV | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2013-2465 | 9.8 | 99.9 | KEV | Oracle Java SE |
| CVE-2019-1003030 | 9.9 | 99.9 | KEV | Jenkins Matrix Project Plugin |
| CVE-2013-0431 | 3.7 | 99.8 | KEV | Oracle Java Runtime Environment (JRE) |
| CVE-2025-40536 | 8.1 | 99.5 | KEV | SolarWinds Web Help Desk Security Control Bypass Vulnerability |
| CVE-2025-0411 | 7.0 | 99.3 | KEV | 7-Zip Mark-of-the-Web Bypass Vulnerability |
| CVE-2024-29988 | 8.8 | 98.7 | KEV | SmartScreen Prompt Security Feature Bypass Vulnerability |
| CVE-2026-21510 | 8.8 | 97.8 | KEV | Windows Shell Security Feature Bypass Vulnerability |
| CVE-2026-21513 | 8.8 | 96.8 | KEV | MSHTML Framework Security Feature Bypass Vulnerability |
| CVE-2024-38213 | 6.5 | 96.4 | KEV | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-38217 | 5.4 | 95.5 | KEV | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-32202 | 4.3 | 91.8 | KEV | Windows Shell Spoofing Vulnerability |
| CVE-2024-38226 | 7.3 | 85.2 | KEV | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2026-58704 | 8.8 | 46.4 | KEV | — |
| CVE-2026-50646 | 7.8 | 90.3 | — | .NET Framework Remote Code Execution Vulnerability |
| CVE-2023-38157 | 6.5 | 83.9 | — | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-27893 | 8.8 | 77.8 | — | vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user securit… |
| CVE-2025-27472 | 5.4 | 75.4 | — | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-30052 | 4.7 | 70.6 | — | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-41316 | 8.1 | 69.6 | — | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 120 | |
| mozilla | 39 |
| microsoft | 38 |
| apple | 22 |
| patriksimek | 14 |
| mervinpraison | 9 |
| twigphp | 9 |
| jenkins project | 8 |
| dell | 5 |
| electron | 4 |
| apache | 3 |
| cure53 | 3 |
| ibm | 3 |
| jahlives | 3 |
| palo alto networks | 3 |