We have discovered 2,714,067 live websites that are affected by CWE-287.
| 699,015 websites | |
| 309,031 websites | |
| 153,118 websites | |
| 115,947 websites | |
| 107,184 websites | |
| 103,171 websites | |
| 99,194 websites | |
| 92,292 websites | |
| 73,778 websites | |
| 66,060 websites |
| .com | 1,029,675 websites |
| .de | 183,378 websites |
| .org | 115,764 websites |
| .net | 97,045 websites |
| .ru | 92,209 websites |
| .nl | 79,237 websites |
| .it | 76,742 websites |
| .cz | 55,241 websites |
| .fr | 53,181 websites |
| .pl | 47,653 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jul, 2025 | CVE-2025-49812 | Apache HTTP Server: mod_ssl TLS upgrade attack | 2,007,320 |
| Jul, 2025 | CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | 2,766 |
| May, 2025 | CVE-2024-13482 | Icegram Engage < 3.1.32 - Admin+ Stored XSS | 1,879 |
| Apr, 2025 | CVE-2025-46348 | YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download | 75 |
| Apr, 2025 | CVE-2024-11917 | JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins | 363 |
| Apr, 2025 | CVE-2025-25227 | [20250402] - Joomla Core - MFA Authentication Bypass | 644 |
| Mar, 2025 | CVE-2024-11087 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass | 132 |
| Mar, 2025 | CVE-2025-1475 | WPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone' | 150 |
| Feb, 2025 | CVE-2025-23419 | TLS Session Resumption Vulnerability | 178,418 |
| Jan, 2025 | CVE-2025-22146 | Improper authentication on SAML SSO process allows user impersonation in sentry | 44 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jul, 2025 | CVE-2025-49812 | Apache HTTP Server: mod_ssl TLS upgrade attack | 2,007,320 |
| Apr, 2024 | CVE-2023-47504 | WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability | 449,371 |
| Feb, 2025 | CVE-2025-23419 | TLS Session Resumption Vulnerability | 178,418 |
| Sep, 2024 | CVE-2024-7870 | PixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion | 50,954 |
| Dec, 2023 | CVE-2023-6203 | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read | 19,495 |
| Oct, 2024 | CVE-2024-9947 | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider | 7,885 |
| Jul, 2024 | CVE-2024-6695 | profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation | 5,987 |
| May, 2023 | CVE-2023-32243 | WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation | 5,150 |
| Nov, 2024 | CVE-2024-9946 | Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider | 3,778 |
| Feb, 2024 | CVE-2024-21410 | Microsoft Exchange Server Elevation of Privilege Vulnerability | 3,184 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| ****.******.org | *** | ||
| *************.***.****.****.************.net | *** | ||
| *****.***********.com | *** | ||
| **********.com | *** | ||
| ********.****.com | *** | ||
| ****.****.******.org | *** | ||
| *********.net | *** | ||
| *****.cz | *,*** | ||
| ***.****.us | *,*** |