Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-201 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 82 | 82 | 0 |
▁▁▁▂█▆▅
2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 32 · 2026-07 24 · 2026-08 19
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47717 | 7.5 | 65.8 | — | FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device C… |
| CVE-2026-44487 | 8.2 | 49.0 | — | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redire… |
| CVE-2026-32829 | 8.2 | 46.5 | — | lz4_flex: Decompression can leak information from uninitialized memory or reused output… |
| CVE-2026-64643 | 6.3 | 41.8 | — | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints |
| CVE-2026-16637 | 6.5 | 38.0 | — | OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects |
| CVE-2026-4035 | 7.7 | 36.5 | — | Environment Variable Resolution Vulnerability in mlflow/mlflow |
| CVE-2026-65543 | 7.5 | 33.2 | — | WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-66443 | 7.5 | 33.1 | — | WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-27868 | 6.9 | 32.7 | — | PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT |
| CVE-2026-42505 | 5.3 | 31.5 | — | Invoking Encrypted Client Hello privacy leak in crypto/tls |
| CVE-2026-39480 | 7.5 | 30.9 | — | WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-57347 | 6.5 | 30.4 | — | WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability |
| CVE-2026-65434 | 6.5 | 28.8 | — | WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability |
| CVE-2025-69132 | 6.5 | 27.7 | — | WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-57318 | 6.5 | 27.7 | — | WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability |
| CVE-2026-66901 | 7.5 | 26.3 | — | Google::Auth versions before 0.09 for Perl allow server side request forgery and creden… |
| CVE-2026-6267 | 5.3 | 26.3 | — | Insertion of Sensitive Information Into Sent Data in GitLab |
| CVE-2026-48965 | 6.5 | 25.6 | — | WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability |
| CVE-2026-55180 | 6.5 | 25.6 | — | pnpm: Repository config can expand victim environment secrets into registry requests be… |
| CVE-2026-67425 | 8.6 | 24.8 | — | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url |
| Vendor | CVEs |
|---|---|
| red hat | 3 |
| devolutions | 2 |
| guzzle | 2 |
| acacode | 1 |
| akshay menariya | 1 |
| al monsor | 1 |
| alex | 1 |
| appsbd | 1 |
| arraytics | 1 |
| atlas educational software industry ltd. co | 1 |
| averta | 1 |
| axios | 1 |
| bookly | 1 |
| bootstrapped ventures | 1 |
| bricksforge | 1 |