Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-178 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 30 | 29 | 1 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁█▅▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 0 · 2026-06 13 · 2026-07 7 · 2026-08 8
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-12812 | 9.8 | 98.8 | KEV | Fortinet FortiOS |
| CVE-2026-58057 | 2.3 | 67.5 | — | Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity |
| CVE-2026-49336 | 5.5 | 65.1 | — | @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redir… |
| CVE-2026-45062 | 8.1 | 44.6 | — | FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F… |
| CVE-2026-3833 | 7.4 | 44.4 | — | Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison |
| CVE-2026-45135 | 8.1 | 40.8 | — | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files |
| CVE-2026-48595 | 8.2 | 40.0 | — | Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Midd… |
| CVE-2026-73416 | 6.1 | 40.0 | — | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
| CVE-2026-47203 | 2.9 | 37.8 | — | Authelia Missing Username Canonicalization in Basic Auth (LDAP) |
| CVE-2026-72721 | 5.3 | 35.9 | — | Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison |
| CVE-2026-53595 | 9.4 | 30.7 | — | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on… |
| CVE-2026-54528 | 7.1 | 28.2 | — | jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories |
| CVE-2026-72836 | 9.2 | 25.0 | — | FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass |
| CVE-2026-53721 | 8.8 | 22.0 | — | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and… |
| CVE-2026-15573 | 8.1 | 21.6 | — | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matchin… |
| CVE-2026-66883 | 6.3 | 21.6 | — | Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup |
| CVE-2026-8404 | 2.3 | 21.0 | — | Potential exposure of private data via case-sensitive Cache-Control directives in Updat… |
| CVE-2026-48794 | 1.3 | 20.9 | — | Authelia has an Edge Case Access Control Rule Mismatch |
| CVE-2026-62230 | 8.7 | 20.8 | — | Grav < 2.0.4 File Access Bypass via Case Variation |
| CVE-2026-15617 | 9.1 | 20.4 | — | Principal/domain lookup without case normalization |
| Vendor | CVEs |
|---|---|
| authelia | 2 |
| getgrav | 2 |
| jupyterlab | 2 |
| nuxt | 2 |
| red hat | 2 |
| aiven-open | 1 |
| caddyserver | 1 |
| discourse | 1 |
| djangoproject | 1 |
| elixir-tesla | 1 |
| erlang ecosystem foundation | 1 |
| filebrowser | 1 |
| flowise | 1 |
| freescout-help-desk | 1 |
| haxtheweb | 1 |