Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-180 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 15 | 0 |
▂▂▅▆█
2026-04 1 · 2026-05 1 · 2026-06 3 · 2026-07 4 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-39364 | 8.2 | 80.2 | — | Vite has a `server.fs.deny` bypass with queries |
| CVE-2026-73420 | 9.1 | 42.5 | — | NextAuth.js: Email normalizer validates the address before Unicode normalization, allow… |
| CVE-2026-52747 | 8.6 | 42.0 | — | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-… |
| CVE-2026-73416 | 6.1 | 40.0 | — | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
| CVE-2026-49984 | 7.7 | 38.1 | — | Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrar… |
| CVE-2026-15704 | 9.8 | 28.5 | — | CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse Ba… |
| CVE-2026-62999 | 7.5 | 22.1 | — | Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (… |
| CVE-2026-72917 | 5.9 | 19.1 | — | AnythingLLM: Password recovery accepts one recovery code twice after whitespace normali… |
| CVE-2026-7120 | 5.3 | 12.9 | — | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths |
| CVE-2026-69246 | 7.2 | 12.0 | — | Guzzle: Noncanonical host can bypass host-based checks |
| CVE-2026-42462 | 7.0 | 6.8 | — | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-45022 | 7.0 | 5.6 | — | go-git: Improper parsing of specially crafted objects may lead to inconsistent interpre… |
| CVE-2026-48721 | 8.6 | 4.2 | — | Warp: Env-var prefixes can lead to denylisted command autoexecution |
| CVE-2026-69245 | 6.5 | 3.6 | — | Guzzle: Noncanonical cookie domain keeps subdomain scope |
| CVE-2026-76203 | 5.1 | — | — | CSS sanitizer bypass in Pentestify report themes allows forced outbound requests |
| Vendor | CVEs |
|---|---|
| guzzle | 2 |
| @auth | 1 |
| @fastify/static | 1 |
| copier-org | 1 |
| eclipse foundation | 1 |
| fedify-dev | 1 |
| go-git | 1 |
| jupyterlab | 1 |
| kestra-io | 1 |
| maalfer | 1 |
| mintplex-labs | 1 |
| nextauthjs | 1 |
| owasp-modsecurity | 1 |
| vitejs | 1 |
| warpdotdev | 1 |