Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1392 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 17 | 0 |
▂▁▁▂▁▅▆█▁
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 5 · 2026-07 7 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58453 | 9.3 | 75.2 | — | JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc |
| CVE-2026-41939 | 9.3 | 53.8 | — | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly |
| CVE-2026-58466 | 9.3 | 41.1 | — | AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user() |
| CVE-2026-44761 | 9.1 | 38.6 | — | Insecure Sample Credentials in SAP Commerce Cloud |
| CVE-2026-68503 | 9.8 | 32.9 | — | LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard |
| CVE-2026-31837 | 8.7 | 31.1 | — | Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch … |
| CVE-2018-25147 | 9.3 | 27.9 | — | Microhard Systems IPn4G 1.1.0 Default Credentials Authentication Bypass |
| CVE-2026-46386 | 9.9 | 19.7 | — | OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default… |
| CVE-2025-36221 | 7.5 | 19.1 | — | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-45039 | 9.8 | 19.1 | — | RustFS: Internode RPC HMAC secret falls back to public default credential, enabling pee… |
| CVE-2026-9844 | 8.8 | 15.3 | — | Vulnerability in navify® Digital Pathology |
| CVE-2026-3144 | 9.8 | 14.6 | — | IBM API Connect Default Credentials |
| CVE-2026-42941 | 8.7 | 13.6 | — | MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials |
| CVE-2026-50005 | 8.3 | 9.8 | — | Brickcom Cameras Use of Default Credentials |
| CVE-2026-65313 | 8.1 | 7.5 | — | Use of hard-coded VNC credentials in the engineering-workstation provisioning |
| CVE-2026-7365 | 7.8 | 2.4 | — | IBM Operations Analytics - Log Analysis is affected by Information disclosure due to de… |
| CVE-2026-44273 | 4.4 | 1.2 | — | — |
| CVE-2026-32652 | 7.8 | 0.9 | — | — |
| Vendor | CVEs |
|---|---|
| ibm | 3 |
| dell | 2 |
| andritz | 1 |
| brickcom | 1 |
| care everywhere | 1 |
| danelec | 1 |
| estrellaxd | 1 |
| grisuno | 1 |
| istio | 1 |
| jaiotlink | 1 |
| microhard systems | 1 |
| opf | 1 |
| roche diagnostics | 1 |
| rustfs | 1 |
| sap_se | 1 |