Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-940
Weakness type CWE-940 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 14 | 1 |
Monthly trend
▄▁▁▁▁▁▁▄▇▂▄█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 1 · 2026-08 2 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-61932 | 9.3 | 85.8 | KEV | Motex LANSCOPE Endpoint Manager |
| CVE-2026-78685 | 8.6 | 48.6 | — | Le-yan|Medical Practice Management System - Remote Code Execution |
| CVE-2026-54106 | 5.1 | 40.1 | — | U.S. GAO EPDS and CBCA EDS network access control bypass |
| CVE-2026-102117 | 7.2 | 34.2 | — | Kiteworks Core Remote Code Execution |
| CVE-2026-48745 | 9.3 | 33.1 | — | Traccar Client: silent configuration hijack via unverified deep link redirects all GPS … |
| CVE-2026-85085 | 9.6 | 30.9 | — | — |
| CVE-2026-6734 | 8.8 | 30.3 | — | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-89178 | 8.7 | 27.1 | — | Howyar|WeenyGenius - Origin Validation Error |
| CVE-2026-85125 | 5.1 | 24.7 | — | — |
| CVE-2026-55660 | 7.6 | 18.5 | — | TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable… |
| CVE-2026-73419 | 6.8 | 14.7 | — | NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider t… |
| CVE-2025-43280 | 4.7 | 10.3 | — | — |
| CVE-2026-44894 | 7.5 | 7.9 | — | Netty's Default QUIC token handler accepts any client-supplied token |
| CVE-2026-102511 | 8.5 | 6.6 | — | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed r… |
| CVE-2026-45353 | 9.3 | 5.5 | — | electerm: Local code through electerm's single-instance socket |
| CVE-2026-44698 | 8.3 | 5.1 | — | Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge cal… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| @auth | 1 |
| apache | 1 |
| apple | 1 |
| canva | 1 |
| civilian board of contract appeals | 1 |
| electerm | 1 |
| government accountability office | 1 |
| home assistant | 1 |
| home-assistant | 1 |
| howyar | 1 |
| kiteworks | 1 |
| le-yan | 1 |
| motex | 1 |
| netty | 1 |
| nextauthjs | 1 |