Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1220 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 18 | 2 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃█▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 2 · 2026-07 8 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33825 | 7.8 | 93.4 | KEV | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-56155 | 7.8 | 82.2 | KEV | Active Directory Federation Services Elevation of Privilege Vulnerability |
| CVE-2026-49170 | 7.8 | 85.3 | — | Windows StateRepository API Server file Elevation of Privilege Vulnerability |
| CVE-2024-43604 | 5.7 | 62.9 | — | Outlook for Android Elevation of Privilege Vulnerability |
| CVE-2026-40365 | 8.8 | 58.8 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-50502 | 8.8 | 46.1 | — | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-68868 | 6.5 | 44.7 | — | Apache Airflow Google provider: google Secret Manager backend: team scope is never appl… |
| CVE-2026-9088 | 2.7 | 28.0 | — | Keycloak: keycloak: information disclosure due to user profile permission bypass |
| CVE-2026-2651 | 9.0 | 27.7 | — | Missing Authorization Validation in mlflow/mlflow |
| CVE-2026-62721 | 7.8 | 25.1 | — | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
| CVE-2026-14615 | 2.7 | 24.5 | — | Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child … |
| CVE-2026-16560 | 5.3 | 15.9 | — | 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn |
| CVE-2026-35436 | 8.8 | 12.7 | — | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-48581 | 7.8 | 12.1 | — | Surface Broker SDMA Elevation of Privilege Vulnerability |
| CVE-2026-50405 | 7.8 | 12.1 | — | Windows Filtering Platform Elevation of Privilege Vulnerability |
| CVE-2026-55006 | 7.8 | 12.1 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-40145 | 7.1 | 1.4 | — | Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deploy… |
| CVE-2021-46747 | 7.1 | 0.8 | — | — |
| CVE-2025-31938 | 4.3 | 0.4 | — | — |