Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 27 | 25 | 0 |
▂▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▆█▅▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 5 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-5946 | 7.5 | 77.7 | — | Invalid handling of CLASS != IN |
| CVE-2026-44249 | 8.1 | 60.9 | — | Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking |
| CVE-2026-24307 | 9.3 | 54.0 | — | M365 Copilot Information Disclosure Vulnerability |
| CVE-2023-3904 | 4.3 | 52.2 | — | Improper Validation of Specified Type of Input in GitLab |
| CVE-2026-50524 | 7.5 | 47.6 | — | .NET Framework Denial of Service Vulnerability |
| CVE-2023-3906 | 3.5 | 39.7 | — | Improper Validation of Specified Type of Input in GitLab |
| CVE-2026-21932 | 7.4 | 37.1 | — | — |
| CVE-2026-55124 | 5.5 | 35.2 | — | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44935 | 9.9 | 34.5 | — | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFr… |
| CVE-2026-9521 | 2.9 | 33.5 | — | fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified ty… |
| CVE-2026-9742 | 8.2 | 27.8 | — | Authenticate command with specific mechanism parameter can trigger server crash |
| CVE-2026-49941 | 7.5 | 25.9 | — | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses |
| CVE-2026-4773 | 8.1 | 24.8 | — | OTP Bypass in Magarsus' IDM-MFA |
| CVE-2026-11460 | 2.9 | 23.8 | — | Boost Serialization improper validation of specified type of input |
| CVE-2026-9753 | 7.2 | 22.4 | — | Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. |
| CVE-2026-18830 | 8.6 | 21.6 | — | Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API |
| CVE-2026-9390 | 9.1 | 20.8 | — | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup |
| CVE-2026-54235 | 6.9 | 19.3 | — | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU k… |
| CVE-2026-4646 | 4.3 | 16.7 | — | Insufficient input validation in GitHub plugin API causes denial of service |
| CVE-2026-10825 | 7.1 | 15.4 | — | Improper JSON Input Validation in WebSocket API Leads to Denial of Service |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| gitlab | 2 |
| mongodb | 2 |
| arista networks | 1 |
| aws | 1 |
| axis communications ab | 1 |
| boost | 1 |
| concrete cms | 1 |
| fraillt | 1 |
| helmholz | 1 |
| honojs | 1 |
| isc | 1 |
| magarsus consulting ltd. co | 1 |
| mattermost | 1 |
| mb connect line | 1 |