Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-798
Weakness type CWE-798 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 203 | 189 | 9 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▃▅▄▆█▃
2025-11 1 · 2025-12 4 · 2026-01 2 · 2026-02 1 · 2026-03 2 · 2026-04 1 · 2026-05 16 · 2026-06 31 · 2026-07 27 · 2026-08 41 · 2026-09 56 · 2026-10 12
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-26138 | 9.8 | 99.9 | KEV | Atlassian Confluence |
| CVE-2024-3272 | 9.8 | 99.9 | KEV | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded c… |
| CVE-2024-28987 | 9.1 | 99.8 | KEV | SolarWinds Web Help Desk Hardcoded Credential Vulnerability |
| CVE-2020-8657 | 9.8 | 99.8 | KEV | EyesOfNetwork EyesOfNetwork |
| CVE-2022-28810 | 6.8 | 99.4 | KEV | Zoho ManageEngine |
| CVE-2025-14611 | 7.1 | 99.0 | KEV | Gladinet CentreStack and TrioFox Hard Coded AES Keys |
| CVE-2021-44207 | 8.1 | 97.1 | KEV | Acclaim Systems USAHERDS |
| CVE-2026-22769 | 10.0 | 96.3 | KEV | Dell RecoverPoint for Virtual Machines (RP4VMs) |
| CVE-2019-6693 | 6.5 | 92.9 | KEV | Fortinet FortiOS |
| CVE-2026-19900 | 8.2 | 86.7 | — | LB-LINK X-PRO shadow hard-coded credentials |
| CVE-2026-44825 | 9.8 | 86.2 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-56265 | 9.3 | 85.1 | — | Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key |
| CVE-2026-73519 | 9.3 | 68.2 | — | WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret |
| CVE-2026-67614 | 9.3 | 60.3 | — | CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal |
| CVE-2024-10451 | 5.9 | 59.1 | — | Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process |
| CVE-2025-69425 | 10.0 | 57.1 | — | Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE |
| CVE-2025-63823 | 9.8 | 55.5 | — | — |
| CVE-2026-55579 | 9.8 | 54.8 | — | Pheditor: Hardcoded default password 'admin' with no forced change enables full applica… |
| CVE-2026-71801 | 9.8 | 54.8 | — | — |
| CVE-2026-54767 | 9.1 | 54.5 | — | WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 9 |
| ibm | 9 |
| open ises | 5 |
| acer | 4 |
| jahlives | 3 |
| lightstar | 3 |
| mervinpraison | 3 |
| watchguard | 3 |
| aiyiyi121 | 2 |
| aqara | 2 |
| autel | 2 |
| bitnami | 2 |
| bransys | 2 |
| digital watchdog | 2 |
| dromara | 2 |