Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-99
Weakness type CWE-99 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 17 | 0 |
Monthly trend
▅█▃▆█▆
2026-05 2 · 2026-06 4 · 2026-07 1 · 2026-08 3 · 2026-09 4 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-62910 | 8.8 | 61.7 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-100884 | 2.1 | 39.6 | — | Krayin laravel-crm attachment-download Endpoint acl.php resource injection |
| CVE-2026-9438 | 2.1 | 35.2 | — | yashpokharna2555 StudentManagementSystem courseDel.php resource injection |
| CVE-2026-15186 | 2.1 | 33.5 | — | macrozheng mall Portal Endpoint create resource injection |
| CVE-2026-94149 | 2.1 | 29.8 | — | Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection |
| CVE-2026-13493 | 1.3 | 28.3 | — | AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection |
| CVE-2026-81521 | 7.1 | 27.3 | — | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWri… |
| CVE-2026-95847 | 8.8 | 25.5 | — | Moquette client IDs can cause cross-session H2 durable-queue corruption |
| CVE-2026-3855 | 6.8 | 25.5 | — | Improper Control of Resource Identifiers ('Resource Injection') in GitLab |
| CVE-2026-10299 | 2.0 | 18.2 | — | code-projects Online Hospital Management System viewdoctortimings.php resource injection |
| CVE-2026-81524 | 5.3 | 17.2 | — | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C D… |
| CVE-2026-10168 | 2.1 | 14.2 | — | OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource in… |
| CVE-2026-10624 | 2.1 | 14.1 | — | SourceCodester Human Resource Management Employee View detailview.php resource injection |
| CVE-2026-105444 | 2.1 | 13.5 | — | dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection |
| CVE-2026-12207 | 2.1 | 12.2 | — | medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource inj… |
| CVE-2026-106583 | 2.5 | 2.1 | — | — |
| CVE-2026-107448 | 3.4 | — | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| mongodb | 2 |
| aidc-ai | 1 |
| code-projects | 1 |
| dotnet | 1 |
| gitlab | 1 |
| krayin | 1 |
| macrozheng | 1 |
| medkey-org | 1 |
| microsoft | 1 |
| moquette-io | 1 |
| omega solution | 1 |
| openbsd | 1 |
| ousl-group-brinarybrains | 1 |
| sourcecodester | 1 |
| wizards of the coast | 1 |