Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-863 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 666 | 649 | 3 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▆
2025-09 1 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 4 · 2026-04 2 · 2026-05 56 · 2026-06 143 · 2026-07 250 · 2026-08 192
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-20269 | 9.1 | 97.4 | KEV | Cisco Adaptive Security Appliance and Firepower Threat Defense |
| CVE-2023-21715 | 7.3 | 95.8 | KEV | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2022-41091 | 5.4 | 79.0 | KEV | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-47996 | 6.8 | 97.2 | — | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-47997 | 5.9 | 94.8 | — | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2025-20701 | 8.8 | 93.6 | — | — |
| CVE-2026-47929 | 8.4 | 80.1 | — | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-71362 | 9.1 | 68.2 | — | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2023-4853 | 8.1 | 66.1 | — | Quarkus: http security policy bypass |
| CVE-2024-6592 | 9.3 | 64.6 | — | WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass |
| CVE-2026-43999 | 9.9 | 59.3 | — | vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb… |
| CVE-2025-24233 | 9.8 | 59.3 | — | — |
| CVE-2026-48286 | 10.0 | 55.9 | — | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-43945 | 8.9 | 55.7 | — | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection |
| CVE-2025-48044 | 8.6 | 53.9 | — | Authorization bypass when bypass policy condition evaluates to true |
| CVE-2026-47101 | 8.7 | 51.8 | — | LiteLLM < 1.83.14 Privilege Escalation via API Key Generation |
| CVE-2026-47303 | 8.8 | 51.6 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-41283 | 9.9 | 51.5 | — | — |
| CVE-2026-56075 | 8.7 | 50.6 | — | PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override |
| CVE-2026-47988 | 8.6 | 49.1 | — | Adobe Commerce | Incorrect Authorization (CWE-863) |
| Vendor | CVEs |
|---|---|
| openclaw | 32 |
| adobe | 31 |
| gitlab | 19 |
| gitea | 18 |
| apache | 15 |
| mattermost | 15 |
| openstack | 14 |
| red hat | 12 |
| grokability | 11 |
| microsoft | 11 |
| elastic | 10 |
| open-webui | 10 |
| surrealdb | 10 |
| misp | 9 |
| mongodb | 9 |