Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-150 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 23 | 0 |
▂▁▁▂▂█▃▆
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 3 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-64654 | 5.3 | 51.7 | — | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands |
| CVE-2026-11373 | 9.1 | 44.6 | — | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections |
| CVE-2026-26149 | 9.0 | 44.4 | — | Microsoft Power Apps Desktop Client Spoofing Vulnerability |
| CVE-2026-21521 | 7.4 | 40.9 | — | Word Copilot Information Disclosure Vulnerability |
| CVE-2026-73414 | 9.2 | 39.5 | — | Shescape: Shell injection via unescaped parentheses on Windows with CMD |
| CVE-2026-11362 | 9.8 | 37.3 | — | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags |
| CVE-2026-62948 | 9.6 | 29.0 | — | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN… |
| CVE-2026-50638 | 9.1 | 27.4 | — | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against… |
| CVE-2026-9270 | 9.1 | 26.1 | — | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections |
| CVE-2026-49147 | 7.5 | 25.9 | — | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences f… |
| CVE-2026-46740 | 5.3 | 25.5 | — | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections |
| CVE-2026-50637 | 8.2 | 25.2 | — | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against me… |
| CVE-2026-50639 | 6.5 | 18.4 | — | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against … |
| CVE-2026-46741 | 7.5 | 18.1 | — | Etsy::StatsD versions through 1.002002 for Perl allow metric injections |
| CVE-2026-46739 | 5.3 | 17.7 | — | Net::Statsd versions before 0.13 for Perl allow metric injections |
| CVE-2026-73035 | 5.3 | 12.1 | — | npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences |
| CVE-2026-8722 | 6.5 | 10.7 | — | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections |
| CVE-2026-39879 | 7.1 | 6.9 | — | SQL injection in syslog-ng SQL destionation driver |
| CVE-2026-54057 | 7.3 | 6.4 | — | Kitty vulnerable to command injection via unsanitized OSC 21 query reply |
| CVE-2026-72913 | 7.3 | 4.4 | — | Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS … |
| Vendor | CVEs |
|---|---|
| pevans | 3 |
| binary | 2 |
| kovidgoyal | 2 |
| microsoft | 2 |
| bash-it | 1 |
| cli | 1 |
| cosimo | 1 |
| ericcornelissen | 1 |
| jandedobbeleer | 1 |
| jasei | 1 |
| openwrt | 1 |
| petdance | 1 |
| raineorshine | 1 |
| romkatv | 1 |
| rrwo | 1 |