Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-15 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 13 | 0 |
▅█▆█
2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45087 | 10.0 | 71.7 | — | Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode |
| CVE-2026-44417 | 7.5 | 47.9 | — | Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to … |
| CVE-2019-25716 | 7.1 | 34.7 | — | Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet |
| CVE-2026-16708 | 8.3 | 34.3 | — | IBM Db2 Mirror for i is affected by multiple vulnerabilities |
| CVE-2026-73661 | 8.6 | 26.5 | — | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup |
| CVE-2026-46485 | 8.2 | 23.1 | — | Dash: Users can write to config despire permissions (OIDC tested) |
| CVE-2026-66065 | 8.4 | 22.3 | — | Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing key… |
| CVE-2026-46399 | 9.4 | 21.6 | — | Authenticated Remote Code Execution via File Overwrite |
| CVE-2026-0418 | 4.3 | 16.0 | — | Certain NETGEAR devices allow administrators to tamper with system |
| CVE-2026-1784 | 8.8 | 9.5 | — | Ose-cluster-ingress-operator: remote code execution through haproxy configuration injec… |
| CVE-2026-44768 | 4.1 | 6.2 | — | Security misconfiguration in SAP CRM (WebClient UI) |
| CVE-2026-19884 | 8.4 | 3.1 | — | — |
| CVE-2026-56567 | 3.3 | 1.0 | — | HCL iControl is affected by multiple security vulnerabilities. |