Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-799
Weakness type CWE-799 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 16 | 0 |
Monthly trend
▃▃▆█▁
2026-06 2 · 2026-07 2 · 2026-08 5 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-19898 | 2.9 | 53.4 | — | VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent… |
| CVE-2026-93650 | 2.9 | 51.1 | — | Saleor throttling.py get_client_ip excessive authentication |
| CVE-2026-75773 | 2.9 | 49.5 | — | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication |
| CVE-2026-19895 | 2.9 | 48.3 | — | opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive auth… |
| CVE-2026-19897 | 2.9 | 45.3 | — | mangroup dtale Login Endpoint auth.py login excessive authentication |
| CVE-2026-54738 | 6.5 | 44.6 | — | Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo |
| CVE-2026-85586 | 6.9 | 40.2 | — | phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter |
| CVE-2026-54594 | 5.3 | 37.0 | — | OmniBlocks: Spamming in Discussions tab possible via disc.yml |
| CVE-2026-10216 | 2.9 | 32.6 | — | unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication |
| CVE-2024-23565 | 5.3 | 32.1 | — | — |
| CVE-2026-33434 | 7.1 | 32.0 | — | Wazuh: Rate Limit Bypass via /events Endpoint |
| CVE-2026-5233 | 7.1 | 27.3 | — | Missing Rate Limiting in Mia Technologies' Pizzy Library |
| CVE-2026-84461 | 6.9 | 23.2 | — | Zammad: Missing rate limiting allows password brute-forcing during two-factor login |
| CVE-2026-100603 | 8.7 | 19.9 | — | ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports |
| CVE-2025-36045 | 4.3 | 16.3 | — | TS4300 Tape Library addresses security vulnerability |
| CVE-2025-13882 | 5.3 | 14.6 | — | Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager. |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 2 |
| hclsoftware | 1 |
| karakeep-app | 1 |
| lemmynet | 1 |
| mangroup | 1 |
| mia technology | 1 |
| omniblocks | 1 |
| openclaw | 1 |
| opensourcepos | 1 |
| thorsten | 1 |
| unitedbyai | 1 |
| wazuh | 1 |
| zammad | 1 |