Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-863
Weakness type CWE-863 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1302 | 1270 | 19 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▅▆█▁
2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 16 · 2026-04 4 · 2026-05 59 · 2026-06 142 · 2026-07 250 · 2026-08 328 · 2026-09 447 · 2026-10 21
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-22518 | 10.0 | 100.0 | KEV | Atlassian Confluence Data Center and Server |
| CVE-2023-38035 | 9.8 | 100.0 | KEV | Ivanti Sentry |
| CVE-2024-38856 | 8.1 | 99.9 | KEV | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
| CVE-2019-7192 | 9.8 | 99.8 | KEV | QNAP Photo Station |
| CVE-2025-54253 | 10.0 | 99.8 | KEV | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2026-71362 | 9.1 | 99.8 | KEV | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2021-40655 | 7.5 | 99.7 | KEV | D-Link DIR-605 Router |
| CVE-2018-13382 | 9.1 | 99.6 | KEV | Fortinet FortiOS and FortiProxy |
| CVE-2023-24880 | 4.4 | 99.6 | KEV | Windows SmartScreen Security Feature Bypass Vulnerability |
| CVE-2023-20269 | 9.1 | 97.9 | KEV | Cisco Adaptive Security Appliance and Firepower Threat Defense |
| CVE-2021-3560 | 7.8 | 97.8 | KEV | Red Hat Polkit |
| CVE-2021-30533 | 6.5 | 97.0 | KEV | Google Chromium PopupBlocker |
| CVE-2023-21715 | 7.3 | 96.0 | KEV | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2026-42016 | 8.8 | 95.0 | KEV | Incorrect authorization validation of user token in JFrog Artifactory allows Privilege … |
| CVE-2025-24200 | 6.1 | 91.1 | KEV | Apple iOS and iPadOS |
| CVE-2022-41091 | 5.4 | 77.8 | KEV | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-21287 | 7.5 | 76.7 | KEV | Oracle Agile Product Lifecycle Management (PLM) |
| CVE-2025-21479 | 8.6 | 56.5 | KEV | Incorrect Authorization in Graphics |
| CVE-2025-21480 | 8.6 | 37.6 | KEV | Incorrect Authorization in Graphics Windows |
| CVE-2025-20701 | 8.8 | 95.0 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 127 | |
| openclaw | 59 |
| adobe | 55 |
| apache | 35 |
| gitlab | 24 |
| elastic | 22 |
| grokability | 21 |
| apple | 20 |
| red hat | 20 |
| gitea | 18 |
| mattermost | 17 |
| openstack | 17 |
| microsoft | 15 |
| open-webui | 15 |
| jetbrains | 14 |