Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-732
Weakness type CWE-732 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 154 | 147 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▃▅█▆█▁
2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 2 · 2026-04 4 · 2026-05 11 · 2026-06 21 · 2026-07 39 · 2026-08 28 · 2026-09 38 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-15752 | 7.8 | 98.8 | KEV | Docker Desktop Community Edition |
| CVE-2018-13374 | 4.3 | 98.5 | KEV | Fortinet FortiOS and FortiADC |
| CVE-2022-22960 | 7.8 | 98.4 | KEV | VMware Multiple Products |
| CVE-2021-27070 | 7.3 | 90.5 | — | Windows 10 Update Assistant Elevation of Privilege Vulnerability |
| CVE-2026-32315 | 5.5 | 86.7 | — | motionEye: World-Readable Configuration File Exposes Admin Password Hash |
| CVE-2021-26434 | 7.8 | 57.8 | — | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2026-85887 | 7.7 | 56.4 | — | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-53486 | 9.1 | 53.3 | — | decompress: Archive extraction can create files and links outside the target directory |
| CVE-2026-10591 | 8.6 | 51.3 | — | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths |
| CVE-2026-19583 | 9.9 | 46.9 | — | Velociraptor Required Permissions bypass by using client monitoring queries |
| CVE-2026-44878 | 7.2 | 46.8 | — | Authenticated Path Traversal allows Unauthorized Access in Web Interface |
| CVE-2026-4757 | 7.2 | 45.2 | — | — |
| CVE-2024-45497 | 7.6 | 44.2 | — | Openshift-api: openshift-controller-manager/build: build process in openshift allows ov… |
| CVE-2026-9508 | 10.0 | 43.8 | — | Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar |
| CVE-2026-73664 | 8.6 | 41.1 | — | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module |
| CVE-2026-61892 | 8.7 | 41.1 | — | Weintek cMT3092X Incorrect Permission Assignment for Critical Resource |
| CVE-2026-61155 | 9.1 | 40.3 | — | — |
| CVE-2026-42497 | 7.5 | 38.5 | — | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled pat… |
| CVE-2025-12801 | 6.5 | 38.5 | — | Nfs-utils: rpc.mountd in the nfs-utils privilege escalation |
| CVE-2026-82697 | 2.9 | 37.9 | — | sambitraj Student-Management-System session_start cookie httponly flag |