Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-183 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 15 | 0 |
▂▁█▆▃
2026-04 1 · 2026-05 0 · 2026-06 7 · 2026-07 5 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42043 | 7.2 | 48.9 | — | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo… |
| CVE-2026-3490 | 10.0 | 47.2 | — | picklescan - Universal Blocklist Bypass via pkgutil.resolve_name |
| CVE-2026-46391 | 8.7 | 38.1 | — | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis |
| CVE-2026-54316 | 6.0 | 33.8 | — | Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch |
| CVE-2026-63649 | 4.1 | 25.9 | — | — |
| CVE-2026-50189 | 8.9 | 25.5 | — | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route |
| CVE-2026-67345 | 8.5 | 23.8 | — | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft |
| CVE-2026-67315 | 6.9 | 21.7 | — | axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 |
| CVE-2026-15625 | 2.1 | 20.5 | — | nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete bl… |
| CVE-2026-8918 | 7.1 | 20.5 | — | — |
| CVE-2026-11525 | 3.7 | 15.2 | — | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring m… |
| CVE-2026-46608 | 7.4 | 14.4 | — | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom… |
| CVE-2026-59802 | 6.3 | 9.2 | — | PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload |
| CVE-2026-46341 | 6.1 | 9.1 | — | Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching |
| CVE-2026-66005 | 5.3 | 8.7 | — | Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding |
| Vendor | CVEs |
|---|---|
| axios | 2 |
| anthropics | 1 |
| apify | 1 |
| appsmithorg | 1 |
| asus | 1 |
| dromara | 1 |
| haxtheweb | 1 |
| janhq | 1 |
| nextlevelbuilder | 1 |
| nicolargo | 1 |
| openvpn | 1 |
| passwordpusher | 1 |
| picklescan | 1 |
| undici | 1 |