Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-939
Weakness type CWE-939 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 11 | 11 | 0 |
Monthly trend
█▁▆▁▂
2026-06 6 · 2026-07 0 · 2026-08 4 · 2026-09 0 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21075 | 5.3 | 40.4 | — | — |
| CVE-2026-53407 | 9.8 | 32.9 | — | — |
| CVE-2026-59717 | 4.3 | 29.8 | — | Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing |
| CVE-2026-53408 | 8.1 | 27.8 | — | — |
| CVE-2026-6445 | 8.7 | 26.6 | — | — |
| CVE-2026-73335 | 4.6 | 3.2 | — | — |
| CVE-2026-12065 | 0.3 | 1.0 | — | Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for cu… |
| CVE-2026-12190 | 4.8 | 1.0 | — | Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for cu… |
| CVE-2026-12189 | 1.9 | 1.0 | — | Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for cus… |
| CVE-2026-21062 | 4.8 | 0.6 | — | — |
| CVE-2026-92862 | 4.6 | — | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| samsung mobile | 2 |
| zoom communications | 2 |
| digital agency | 1 |
| everpure | 1 |
| genspark | 1 |
| groww | 1 |
| home-assistant | 1 |
| moovit | 1 |
| wavedash co | 1 |