Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1391 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 8 | 8 | 0 |
████
2026-05 2 · 2026-06 2 · 2026-07 2 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-35089 | 8.7 | 45.6 | — | Use of Weak Credentials in Slican telephone exchanges |
| CVE-2026-66409 | 6.9 | 25.4 | — | — |
| CVE-2026-47325 | 6.9 | 16.5 | — | Weak password policy in ProjectsAndPrograms school-management-system |
| CVE-2026-45363 | 9.1 | 15.6 | — | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-66408 | 5.1 | 10.7 | — | — |
| CVE-2026-57473 | 5.8 | 4.3 | — | — |
| CVE-2026-49852 | 8.7 | 4.1 | — | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of… |
| CVE-2026-4377 | 6.0 | 3.9 | — | Use of Weak Credentials in D-Link DWR-X1820 router |
| Vendor | CVEs |
|---|---|
| ecovacs robotics | 2 |
| authlib | 1 |
| d-link | 1 |
| jwt | 1 |
| projectsandprograms | 1 |
| reolink | 1 |
| slican | 1 |