Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1023 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 1 |
▃▁▁█▃▃
2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 4 · 2026-07 1 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-7473 | 6.9 | 63.3 | KEV | Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass |
| CVE-2026-4599 | 9.3 | 39.3 | — | — |
| CVE-2026-24255 | 7.5 | 31.8 | — | — |
| CVE-2026-48587 | 2.3 | 28.6 | — | Potential exposure of private data via whitespace padding in Vary header |
| CVE-2026-48761 | 5.3 | 19.0 | — | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet… |
| CVE-2026-53839 | 6.0 | 18.5 | — | OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation |
| CVE-2026-53859 | 6.0 | 11.6 | — | OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency |
| Vendor | CVEs |
|---|---|
| openclaw | 2 |
| arista networks | 1 |
| djangoproject | 1 |
| nvidia | 1 |
| symfony | 1 |