Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 10 | 0 |
▃█▁█▃
2026-04 1 · 2026-05 4 · 2026-06 0 · 2026-07 4 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-43001 | 8.0 | 38.7 | — | — |
| CVE-2026-73219 | 5.3 | 27.3 | — | CVAT: Denial of service with regards to automatic annotation |
| CVE-2026-9689 | 4.2 | 25.1 | — | Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri all… |
| CVE-2026-42982 | 7.8 | 19.2 | — | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-31709 | 8.8 | 17.8 | — | smb: client: validate the whole DACL before rewriting it in cifsacl |
| CVE-2026-15943 | 5.5 | 10.0 | — | Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after… |
| CVE-2026-18209 | 4.7 | 9.3 | — | Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http paramet… |
| CVE-2026-14781 | 4.8 | 7.6 | — | Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to … |
| CVE-2026-31488 | 7.8 | 3.8 | — | drm/amd/display: Do not skip unrelated mode changes in DSC validation |
| CVE-2026-46117 | 7.8 | 3.2 | — | RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() |