Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1021 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 31 | 31 | 0 |
▅█▆▇
2026-05 6 · 2026-06 10 · 2026-07 7 · 2026-08 8
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58595 | 8.1 | 38.2 | — | Microsoft Bing App for IOS Spoofing Vulnerability |
| CVE-2026-70486 | 8.2 | 30.7 | — | Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardco… |
| CVE-2026-37470 | 7.3 | 25.3 | — | — |
| CVE-2026-40957 | 6.1 | 24.1 | — | Frameable content vulnerability in the Secure Access server login page |
| CVE-2026-18534 | 7.4 | 23.9 | — | Address bar spoofing risk in affected iOS versions of Arc Search |
| CVE-2026-44727 | 9.3 | 23.2 | — | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missi… |
| CVE-2026-47723 | 7.1 | 23.0 | — | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS… |
| CVE-2026-12348 | 7.4 | 20.8 | — | Address Bar Spoofing in Arc Search for Android (window.open race condition) |
| CVE-2026-9396 | 2.9 | 19.1 | — | Besen BS20 EV Charging Station Firmware Version Check ui layer |
| CVE-2026-74958 | 7.5 | 18.4 | — | Information disclosure in the WebRTC component |
| CVE-2026-70608 | 7.2 | 17.7 | — | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navi… |
| CVE-2026-74978 | 8.1 | 16.3 | — | Clickjacking issue in the Widget component |
| CVE-2026-25681 | 6.1 | 13.2 | — | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/ne… |
| CVE-2026-27136 | 6.1 | 13.2 | — | Invoking duplicate attributes can cause XSS in golang.org/x/net/html |
| CVE-2026-42502 | 6.1 | 13.2 | — | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html |
| CVE-2026-10733 | 4.3 | 12.8 | — | Improper Restriction of Rendered UI Layers or Frames in GitLab |
| CVE-2026-12322 | 5.4 | 11.2 | — | Clickjacking issue in the Widget: Gtk component |
| CVE-2026-60370 | 7.5 | 10.3 | — | — |
| CVE-2026-38979 | 5.4 | 10.1 | — | — |
| CVE-2026-14110 | 4.3 | 9.5 | — | — |
| Vendor | CVEs |
|---|---|
| mozilla | 6 |
| 5 | |
| golang.org/x/net | 3 |
| electron | 2 |
| absolute security | 1 |
| besen | 1 |
| gitlab | 1 |
| hclsoftware | 1 |
| jetbrains | 1 |
| juev | 1 |
| jupyter-server | 1 |
| microsoft | 1 |
| open-webui | 1 |
| oracle | 1 |
| sap_se | 1 |