Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-73
Weakness type CWE-73 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 292 | 277 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅██▂
2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 2 · 2026-03 1 · 2026-04 1 · 2026-05 12 · 2026-06 41 · 2026-07 47 · 2026-08 83 · 2026-09 79 · 2026-10 7
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-33053 | 8.8 | 99.7 | KEV | Internet Shortcut Files Remote Code Execution Vulnerability |
| CVE-2024-43451 | 6.5 | 99.7 | KEV | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2025-24054 | 6.5 | 99.1 | KEV | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2020-1631 | 8.8 | 91.7 | KEV | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based… |
| CVE-2025-0111 | 7.1 | 80.0 | KEV | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface |
| CVE-2026-20872 | 6.5 | 97.4 | — | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2026-20925 | 6.5 | 97.1 | — | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2026-21249 | 3.3 | 95.9 | — | Windows NTLM Spoofing Vulnerability |
| CVE-2025-71334 | 9.3 | 91.0 | — | Flowise - Arbitrary File Access via Missing Chat Flow ID Validation |
| CVE-2026-8450 | 9.1 | 84.9 | — | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() |
| CVE-2025-68428 | 9.2 | 81.7 | — | jsPDF has Local File Inclusion/Path Traversal vulnerability |
| CVE-2025-71324 | 8.7 | 74.5 | — | Flowise - Arbitrary File Read via chatId Parameter |
| CVE-2023-35384 | 6.5 | 74.4 | — | Windows HTML Platforms Security Feature Bypass Vulnerability |
| CVE-2025-4603 | 9.1 | 71.8 | — | eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion |
| CVE-2024-43581 | 7.1 | 71.8 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2024-38029 | 7.5 | 71.6 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2026-11526 | 9.8 | 70.6 | — | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-… |
| CVE-2024-43615 | 7.1 | 68.3 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2025-71338 | 10.0 | 65.9 | — | Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-stor… |
| CVE-2026-77621 | 9.3 | 65.1 | — | Vector: Arbitrary file write in the file sink via templated path (path traversal). |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 33 |
| ibm | 8 |
| lxc | 5 |
| mbs | 5 |
| pnpm | 5 |
| progress | 5 |
| flowise | 4 |
| getgrav | 4 |
| gitpython-developers | 4 |
| red hat | 4 |
| sourcecodester | 4 |
| conda | 3 |
| eclipse foundation | 3 |
| hewlett packard enterprise (hpe) | 3 |
| midnightbsd | 3 |