Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-749
Weakness type CWE-749 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 47 | 41 | 4 |
Monthly trend
▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁▁▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁▁▁▁▁▁▁▁
2025-03 0 · 2025-04 2 · 2025-05 0 · 2025-06 0 · 2025-07 0 · 2025-08 0 · 2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2010-0738 | 5.3 | 99.6 | KEV | Red Hat JBoss |
| CVE-2010-1428 | 7.5 | 99.1 | KEV | Red Hat JBoss |
| CVE-2006-1547 | 7.5 | 99.0 | KEV | Apache Struts 1 |
| CVE-2018-19322 | 7.8 | 77.8 | KEV | GIGABYTE Multiple Products |
| CVE-2025-26651 | 6.5 | 84.3 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability |
| CVE-2026-54753 | 5.9 | 67.2 | — | Nx: `nx graph` dev server permissive CORS policy |
| CVE-2026-77521 | 10.0 | 63.0 | — | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-68823 | 9.1 | 59.3 | — | Azure Confidential Ledger Remote Code Execution Vulnerability |
| CVE-2026-41283 | 9.9 | 58.8 | — | — |
| CVE-2026-53633 | 9.8 | 58.1 | — | Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE |
| CVE-2026-45489 | 6.5 | 57.6 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-18901 | 7.3 | 56.7 | — | H3C NX15 Web API esps service.add routine |
| CVE-2025-53827 | 9.1 | 47.6 | — | ownCloud Core: Updater has an exposed dangerous method or function |
| CVE-2026-55454 | 9.9 | 47.0 | — | Appsmith: Caddy admin API exposed without authentication |
| CVE-2026-89139 | 8.7 | 45.8 | — | Temporal Server worker deployment compute provider executes a caller-supplied command o… |
| CVE-2026-44107 | 8.7 | 44.6 | — | Exposed Reboot via Modbus |
| CVE-2026-48056 | 10.0 | 44.3 | — | Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
| CVE-2026-14620 | 4.7 | 42.2 | — | webpack-dev-server vulnerable to cross-site request forgery via internal developer endp… |
| CVE-2026-4051 | 7.2 | 40.6 | — | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Aut… |
| CVE-2026-44798 | 7.1 | 40.5 | — | Nautobot: GitRepository.current_head field should not be writable through REST API |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| parallels | 3 |
| nuxt | 2 |
| truelockmc | 2 |
| 1panel-dev | 1 |
| acode-foundation | 1 |
| appsmithorg | 1 |
| asus | 1 |
| cisco | 1 |
| convertigo | 1 |
| eclipse foundation | 1 |
| electerm | 1 |
| flowring technology | 1 |
| gitroomhq | 1 |
| h3c | 1 |