Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-185 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
▅▁▁█▅▅█
2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 1 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-56021 | 6.9 | 39.3 | — | Webmin information disclosure via regex pattern |
| CVE-2026-25896 | 9.3 | 38.4 | — | fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names |
| CVE-2026-64655 | 2.1 | 25.9 | — | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN M… |
| CVE-2026-45065 | 2.3 | 18.0 | — | Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-S… |
| CVE-2026-47674 | 5.3 | 15.9 | — | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| CVE-2026-73425 | 3.7 | 6.9 | — | @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePa… |
| CVE-2026-48147 | 6.5 | 1.8 | — | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injecti… |