Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-706
Weakness type CWE-706 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 42 | 39 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 13 · 2026-09 15 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-15505 | 9.8 | 100.0 | KEV | Ivanti MobileIron Multiple Products |
| CVE-2021-40539 | 9.8 | 99.9 | KEV | Zoho ManageEngine |
| CVE-2026-65816 | 10.0 | 60.8 | — | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-81383 | 7.4 | 59.0 | — | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-67602 | 9.3 | 48.8 | — | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache |
| CVE-2026-62685 | 8.1 | 44.2 | — | File Browser: Colliding username normalization gives two users the same home directory |
| CVE-2026-92951 | 9.4 | 43.4 | — | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver |
| CVE-2026-62190 | 8.7 | 41.3 | — | OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper |
| CVE-2026-78985 | 9.6 | 40.9 | — | — |
| CVE-2026-87547 | 9.6 | 40.9 | — | — |
| CVE-2026-13372 | 7.2 | 40.6 | — | — |
| CVE-2026-87613 | 9.0 | 38.5 | — | — |
| CVE-2026-29036 | 8.7 | 36.4 | — | cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding |
| CVE-2026-87618 | 8.3 | 36.1 | — | — |
| CVE-2026-95334 | 8.3 | 36.1 | — | — |
| CVE-2026-13097 | 8.7 | 34.7 | — | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware unique… |
| CVE-2026-45306 | 6.5 | 32.8 | — | pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory |
| CVE-2026-16120 | 2.1 | 31.8 | — | nextlevelbuilder GoClaw exec_approval.go extractBin name resolution |
| CVE-2026-79049 | 4.3 | 28.4 | — | — |
| CVE-2026-57054 | 6.9 | 28.2 | — | Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 17 | |
| devolutions | 2 |
| gitlab | 2 |
| microsoft | 2 |
| davegamble | 1 |
| filebrowser | 1 |
| gerrit | 1 |
| juniper networks | 1 |
| kludex | 1 |
| linux | 1 |
| nextlevelbuilder | 1 |
| notepad-plus-plus | 1 |
| open-webui | 1 |
| openclaw | 1 |
| patriksimek | 1 |