Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-862
Weakness type CWE-862 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 2460 | 2436 | 10 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▆█▂
2025-11 2 · 2025-12 2 · 2026-01 4 · 2026-02 5 · 2026-03 2 · 2026-04 4 · 2026-05 135 · 2026-06 368 · 2026-07 454 · 2026-08 607 · 2026-09 799 · 2026-10 58
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-0543 | 10.0 | 99.9 | KEV | Redis Debian-specific Redis Servers |
| CVE-2023-52163 | 8.8 | 99.9 | KEV | Digiever DS-2105 Pro |
| CVE-2025-20362 | 8.6 | 99.7 | KEV | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense |
| CVE-2025-6205 | 9.1 | 99.5 | KEV | Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through R… |
| CVE-2021-30657 | 5.5 | 99.3 | KEV | Apple macOS |
| CVE-2024-57726 | 9.9 | 99.3 | KEV | SimpleHelp SimpleHelp |
| CVE-2021-37976 | 6.5 | 97.4 | KEV | Google Chromium |
| CVE-2021-30713 | 7.8 | 94.0 | KEV | Apple macOS |
| CVE-2025-40602 | 6.6 | 85.7 | KEV | SonicWall SMA1000 appliance |
| CVE-2026-84869 | 9.9 | 59.1 | KEV | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions |
| CVE-2023-5612 | 5.3 | 91.8 | — | Missing Authorization in GitLab |
| CVE-2026-73296 | 9.4 | 89.3 | — | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control a… |
| CVE-2026-10768 | 9.8 | 81.3 | — | LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039 |
| CVE-2026-6639 | 7.5 | 79.9 | — | AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenti… |
| CVE-2026-11801 | 7.5 | 75.6 | — | WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Dis… |
| CVE-2026-48168 | 10.0 | 73.4 | — | PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name |
| CVE-2026-27771 | 8.2 | 71.4 | — | Gitea Composer package source links use insufficient permission checks |
| CVE-2026-12645 | 8.8 | 69.0 | — | — |
| CVE-2026-55440 | 6.5 | 68.6 | — | Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated… |
| CVE-2026-12646 | 8.8 | 68.1 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 91 | |
| microsoft | 39 |
| red hat | 39 |
| openclaw | 36 |
| misp | 31 |
| siyuan-note | 31 |
| concrete cms | 29 |
| jenkins project | 27 |
| apache | 26 |
| jetbrains | 25 |
| gitlab | 19 |
| mervinpraison | 19 |
| elastic | 18 |
| typo3 | 18 |
| apple | 17 |