Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1188 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 50 | 47 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▇▃
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 7 · 2026-06 19 · 2026-07 16 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47668 | 10.0 | 90.4 | — | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner |
| CVE-2026-67208 | 9.3 | 90.2 | — | Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console |
| CVE-2026-44825 | 9.8 | 80.8 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-54066 | 7.5 | 77.9 | — | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary… |
| CVE-2026-66066 | 9.5 | 76.3 | — | Action Pack: Possible arbitrary file read and remote code execution in Active Storage v… |
| CVE-2026-14474 | 8.8 | 44.6 | — | Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by d… |
| CVE-2025-59321 | 9.8 | 42.9 | — | — |
| CVE-2026-50519 | 7.5 | 41.6 | — | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-63563 | 6.9 | 36.0 | — | — |
| CVE-2026-47393 | 9.8 | 33.8 | — | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-55454 | 9.9 | 32.5 | — | Appsmith: Caddy admin API exposed without authentication |
| CVE-2026-35672 | 8.7 | 31.7 | — | phpMyFAQ - Authentication Bypass via Empty API Token |
| CVE-2026-56285 | 7.7 | 29.2 | — | Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint |
| CVE-2026-62416 | 6.9 | 28.8 | — | — |
| CVE-2025-38523 | 5.5 | 27.6 | — | cifs: Fix the smbd_response slab to allow usercopy |
| CVE-2026-54067 | 9.9 | 23.4 | — | SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() |
| CVE-2026-60024 | 9.8 | 23.0 | — | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5… |
| CVE-2026-45728 | 7.5 | 22.9 | — | Algernon: Single-file mode unconditionally enables debug mode |
| CVE-2026-54158 | 9.9 | 21.5 | — | SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() |
| CVE-2022-2196 | 8.8 | 21.1 | — | Speculative execution attacks in KVM VMX |
| Vendor | CVEs |
|---|---|
| linux | 3 |
| siyuan-note | 3 |
| joomdonation.com | 2 |
| mervinpraison | 2 |
| messagepack-csharp | 2 |
| sharp | 2 |
| vps.org | 2 |
| xyproto | 2 |
| alibaba | 1 |
| apache | 1 |
| appsmithorg | 1 |
| argoproj | 1 |
| canon | 1 |
| dbgate | 1 |
| givanz | 1 |