Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-841
Weakness type CWE-841 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 36 | 35 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▂█▆▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 7 · 2026-07 2 · 2026-08 13 · 2026-09 10 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-67279 | 6.9 | 62.4 | KEV | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
| CVE-2026-43974 | 8.7 | 48.9 | — | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing serve… |
| CVE-2026-55763 | 8.7 | 41.1 | — | Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits |
| CVE-2026-78103 | 5.1 | 40.2 | — | Dimension Log Server Configuration Lock Bypass Vulnerability |
| CVE-2024-0410 | 7.7 | 37.5 | — | Improper Enforcement of Behavioral Workflow in GitLab |
| CVE-2026-46540 | 6.5 | 36.9 | — | Nimiq light-blockchain: Light blockchain rebranch issue |
| CVE-2026-82423 | 2.1 | 35.8 | — | macrozheng mall Payment Status Endpoint paySuccess behavioral workflow |
| CVE-2026-78618 | 6.9 | 35.1 | — | Dimension Business Logic Flaw Allows Chained Backend Object Operations |
| CVE-2026-19208 | 2.9 | 34.7 | — | WonderTrader TraderDD.cpp queryTrades behavioral workflow |
| CVE-2026-95369 | 8.8 | 33.4 | — | — |
| CVE-2026-45023 | 5.4 | 29.2 | — | AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_i… |
| CVE-2026-19037 | 2.1 | 28.3 | — | WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral work… |
| CVE-2026-19213 | 2.1 | 28.3 | — | WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow |
| CVE-2026-19993 | 2.1 | 28.3 | — | Webkul Bagisto RMA State Validation update-status behavioral workflow |
| CVE-2026-75081 | 2.1 | 28.3 | — | Webkul Bagisto store behavioral workflow |
| CVE-2026-53637 | 6.5 | 27.8 | — | Sylius: Cart FormComponent allows modification or deletion of an already-completed order |
| CVE-2026-79083 | 7.5 | 27.8 | — | — |
| CVE-2026-78135 | 7.3 | 27.8 | — | — |
| CVE-2026-80195 | 8.7 | 27.0 | — | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-16103 | 4.3 | 25.7 | — | Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypas… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 5 | |
| pretix | 4 |
| klever-io | 2 |
| watchguard | 2 |
| webkul | 2 |
| devolutions | 1 |
| filamentphp | 1 |
| gitlab | 1 |
| ibm | 1 |
| kimai | 1 |
| macrozheng | 1 |
| mikrotik | 1 |
| nimiq | 1 |
| ninenines | 1 |
| nvidia | 1 |