Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-913
Weakness type CWE-913 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 24 | 23 | 1 |
Monthly trend
▂▁▁▁▁▁▅▁▅█▁
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 6 · 2026-07 0 · 2026-08 6 · 2026-09 11 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-68613 | 10.0 | 99.9 | KEV | n8n Vulnerable to Remote Code Execution via Expression Injection |
| CVE-2026-53753 | 10.0 | 86.5 | — | Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API |
| CVE-2026-47698 | 9.8 | 60.6 | — | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators |
| CVE-2026-92946 | 10.0 | 57.0 | — | vm2 before 3.11.7 Remote Code Execution via require.external |
| CVE-2026-47208 | 10.0 | 55.9 | — | vm2: Sandbox Breakout Using Promise Species |
| CVE-2026-47210 | 9.8 | 55.9 | — | vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass |
| CVE-2026-73226 | 8.8 | 53.4 | — | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function inv… |
| CVE-2026-92955 | 10.0 | 52.0 | — | vm2 before 3.11.8 Sandbox Escape via NodeVM |
| CVE-2026-71470 | 9.1 | 51.8 | — | Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow … |
| CVE-2026-47137 | 10.0 | 51.7 | — | vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allo… |
| CVE-2026-48775 | 6.8 | 50.9 | — | LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading |
| CVE-2026-92935 | 9.5 | 50.4 | — | vm2 NodeVM Remote Code Execution via Array-Shaped Require |
| CVE-2026-90999 | 9.8 | 50.3 | — | Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileg… |
| CVE-2026-41870 | 8.8 | 50.1 | — | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch S… |
| CVE-2026-47131 | 10.0 | 49.3 | — | vm2: Sandbox Escape |
| CVE-2026-59283 | 9.1 | 43.8 | — | Spring Framework Safety Guard Bypass via SpEL Expression Compilation |
| CVE-2026-65181 | 8.1 | 43.5 | — | Apache Impala: RCE via External Data Source Class Loading |
| CVE-2026-92953 | 9.3 | 40.8 | — | vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray |
| CVE-2026-76023 | 8.8 | 37.0 | — | — |
| CVE-2026-92217 | 5.3 | 35.1 | — | a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-dete… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| patriksimek | 9 |
| apache | 2 |
| a2ui-project | 1 |
| basekick-labs | 1 |
| electerm | 1 |
| eleveo | 1 |
| functional software | 1 |
| 1 | |
| ibm | 1 |
| langchain-ai | 1 |
| n8n-io | 1 |
| red hat | 1 |
| spring | 1 |
| unclecode | 1 |