Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-829
Weakness type CWE-829 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 112 | 108 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃██▇▇▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 7 · 2026-06 26 · 2026-07 26 · 2026-08 22 · 2026-09 23 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-0770 | 9.8 | 99.2 | KEV | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote C… |
| CVE-2025-32463 | 9.3 | 99.0 | KEV | Sudo Sudo |
| CVE-2026-59865 | 9.3 | 91.0 | — | Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot… |
| CVE-2026-59867 | 7.1 | 83.4 | — | Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref |
| CVE-2026-73851 | 6.1 | 82.5 | — | Kiota: Path traversal in generated plugin manifest static_template.file reference (perc… |
| CVE-2026-44359 | 10.0 | 77.7 | — | Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target F… |
| CVE-2026-59864 | 9.3 | 70.1 | — | Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions |
| CVE-2026-71471 | 9.0 | 67.6 | — | Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagat… |
| CVE-2026-43003 | 7.5 | 65.2 | — | — |
| CVE-2026-67623 | 8.6 | 63.3 | — | Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook |
| CVE-2026-43999 | 9.9 | 60.6 | — | vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb… |
| CVE-2026-86169 | 8.7 | 59.6 | — | Axolotl before 0.19.0 Remote Code Execution via Multipack Patching |
| CVE-2026-5241 | 9.6 | 59.5 | — | Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers |
| CVE-2026-58116 | 9.3 | 58.4 | — | LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path |
| CVE-2026-62902 | 6.5 | 57.5 | — | .NET Information Disclosure Vulnerability |
| CVE-2026-57102 | 8.8 | 55.7 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-40501 | 8.6 | 55.3 | — | Cherry Studio RCE via SearchService nodeIntegration Misconfiguration |
| CVE-2026-93993 | 8.6 | 54.1 | — | Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout |
| CVE-2026-42510 | 7.2 | 53.0 | — | — |
| CVE-2026-76139 | 8.0 | 52.3 | — | Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/releas… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| jetbrains | 10 |
| microsoft | 9 |
| eclipse foundation | 5 |
| netbox-community | 4 |
| red hat | 4 |
| pnpm | 3 |
| vim | 3 |
| concrete cms | 2 |
| dell | 2 |
| docker | 2 |
| duck-organization | 2 |
| mervinpraison | 2 |
| mistralai | 2 |
| openclaw | 2 |
| openstack | 2 |