Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-177 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 3 | 3 | 0 |
█▅
2026-07 2 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-41041 | 9.1 | 39.2 | — | Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP RES… |
| CVE-2026-59083 | 9.1 | 30.2 | — | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass |
| CVE-2026-15371 | 8.1 | 11.2 | — | Velociraptor Stored XSS in URL column types |