Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-200 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 790 | 748 | 4 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▄
2025-09 1 · 2025-10 0 · 2025-11 4 · 2025-12 0 · 2026-01 10 · 2026-02 3 · 2026-03 2 · 2026-04 11 · 2026-05 41 · 2026-06 170 · 2026-07 348 · 2026-08 163
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-24919 | 8.6 | 100.0 | KEV | Information disclosure |
| CVE-2020-3259 | 7.5 | 99.3 | KEV | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Se… |
| CVE-2026-20805 | 5.5 | 91.7 | KEV | Desktop Window Manager Information Disclosure Vulnerability |
| CVE-2025-68686 | 5.9 | 67.4 | KEV | Fortinet FortiOS |
| CVE-2024-21626 | 8.6 | 97.0 | — | runc container breakout through process.cwd trickery and leaked fds |
| CVE-2026-55450 | 9.3 | 95.7 | — | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
| CVE-2026-50508 | 7.5 | 94.7 | — | Windows NTLM Spoofing Vulnerability |
| CVE-2026-33829 | 4.3 | 88.0 | — | Windows Snipping Tool Spoofing Vulnerability |
| CVE-2026-39363 | 8.2 | 87.6 | — | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket |
| CVE-2026-32625 | 9.6 | 86.0 | — | LibreChat Exfiltrates Server Secrets via MCP Server URL Injection |
| CVE-2023-36894 | 6.5 | 79.9 | — | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2024-43609 | 6.5 | 79.3 | — | Microsoft Office Spoofing Vulnerability |
| CVE-2024-21380 | 8.0 | 75.7 | — | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability |
| CVE-2024-35263 | 5.7 | 74.7 | — | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2025-26667 | 6.5 | 74.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-25037 | 9.3 | 71.1 | — | Aquatronica Controller System Complete Information Disclosure |
| CVE-2026-21260 | 7.5 | 70.8 | — | Microsoft Outlook Spoofing Vulnerability |
| CVE-2025-29805 | 7.5 | 70.5 | — | Outlook for Android Information Disclosure Vulnerability |
| CVE-2026-20847 | 6.5 | 69.3 | — | Microsoft Windows File Explorer Spoofing Vulnerability |
| CVE-2023-38158 | 3.1 | 69.2 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| Vendor | CVEs |
|---|---|
| oracle | 120 |
| microsoft | 88 |
| apple | 34 |
| 31 | |
| apache | 18 |
| capgo | 15 |
| mozilla | 15 |
| discourse | 14 |
| gitea | 13 |
| red hat | 9 |
| ibm | 6 |
| fossbilling | 5 |
| hcl software | 5 |
| hclsoftware | 5 |
| huawei | 5 |