Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-184 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 60 | 58 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▆▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 22 · 2026-07 17 · 2026-08 13
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-30103 | 8.8 | 88.0 | — | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-63108 | 7.7 | 78.2 | — | Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing |
| CVE-2026-49869 | 10.0 | 56.6 | — | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authenticat… |
| CVE-2025-29822 | 7.8 | 53.2 | — | Microsoft OneNote Security Feature Bypass Vulnerability |
| CVE-2026-54512 | 8.1 | 53.1 | — | jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows ar… |
| CVE-2025-71323 | 9.3 | 52.4 | — | picklescan - Remote Code Execution via Unblocked ctypes Module |
| CVE-2026-56315 | 9.3 | 52.4 | — | picklescan - Remote Code Execution via Unblocked Standard Library Modules |
| CVE-2026-54513 | 8.1 | 50.8 | — | jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allo… |
| CVE-2025-71351 | 7.6 | 50.7 | — | picklescan - Remote Code Execution via timeit.timeit() Detection Bypass |
| CVE-2025-71320 | 9.3 | 47.2 | — | picklescan - Remote Code Execution via Incomplete Disallowed Inputs |
| CVE-2026-47392 | 9.9 | 46.2 | — | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `ex… |
| CVE-2025-71355 | 7.6 | 43.8 | — | Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass |
| CVE-2026-41934 | 8.7 | 43.4 | — | Vvveb < 1.0.8.2 Authenticated RCE via Code Editor |
| CVE-2026-70470 | 9.5 | 42.2 | — | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE |
| CVE-2026-53873 | 9.3 | 38.2 | — | picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass |
| CVE-2026-48736 | 6.9 | 38.3 | — | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv… |
| CVE-2026-13448 | 9.8 | 38.0 | — | Langflow is affected by remote code execution, denial of service, path traversal, and e… |
| CVE-2026-53836 | 8.7 | 37.6 | — | OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases |
| CVE-2026-48557 | 8.7 | 36.8 | — | Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php |
| CVE-2026-44462 | 8.8 | 36.7 | — | Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions |
| Vendor | CVEs |
|---|---|
| openclaw | 9 |
| picklescan | 6 |
| flowiseai | 3 |
| symfony | 3 |
| fasterxml | 2 |
| flavorjones | 2 |
| ibm | 2 |
| microsoft | 2 |
| zed-industries | 2 |
| @fastify/forwarded | 1 |
| bytedance | 1 |
| carrierwaveuploader | 1 |
| craftcms | 1 |
| esphome | 1 |
| filebrowser | 1 |