Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-209 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 45 | 45 | 0 |
▂▁▁▁▅▅█▅
2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 8 · 2026-06 10 · 2026-07 16 · 2026-08 8
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-29146 | 7.5 | 93.0 | — | Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default |
| CVE-2026-20838 | 5.5 | 48.7 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-56139 | 5.3 | 42.6 | — | Apache Camel Undertow: The muteException consumer option defaulted to false, so a proce… |
| CVE-2026-49365 | 5.3 | 40.9 | — | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, s… |
| CVE-2025-59872 | 9.8 | 37.8 | — | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, |
| CVE-2026-43630 | 6.3 | 37.8 | — | llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure |
| CVE-2024-28765 | 5.3 | 31.8 | — | Security vulnerability was found in IBM Security Directory Integrator |
| CVE-2026-40997 | 5.3 | 29.8 | — | SOAP security faults leak Spring Security account state |
| CVE-2026-53906 | 5.1 | 27.1 | — | Path Disclosure and Path Traversal in MCO |
| CVE-2026-53458 | 5.3 | 27.0 | — | Blueprint Studio API exposed internal exception details |
| CVE-2026-9794 | 5.3 | 26.2 | — | Keycloak: keycloak: information disclosure via saml ecp endpoint |
| CVE-2026-42459 | 7.7 | 25.4 | — | free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive… |
| CVE-2026-13182 | 7.5 | 24.9 | — | RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP… |
| CVE-2026-66008 | 6.3 | 24.8 | — | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
| CVE-2026-45728 | 7.5 | 22.9 | — | Algernon: Single-file mode unconditionally enables debug mode |
| CVE-2025-1395 | 8.2 | 22.5 | — | Sensitive Data Exposure in CoDeriApp's HeyGarson |
| CVE-2026-11904 | 5.3 | 21.9 | — | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security… |
| CVE-2026-47248 | 6.9 | 21.7 | — | Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthen… |
| CVE-2026-64627 | 6.9 | 20.4 | — | Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion |
| CVE-2026-41935 | 7.1 | 18.9 | — | Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Service |
| Vendor | CVEs |
|---|---|
| ibm | 5 |
| parse-community | 4 |
| apache | 3 |
| hcl software | 3 |
| hclsoftware | 3 |
| givanz | 2 |
| hcl | 2 |
| spring | 2 |
| appsmithorg | 1 |
| capgo | 1 |
| codriapp innovation and software technologies | 1 |
| dompdf | 1 |
| envoyproxy | 1 |
| ericsson | 1 |
| free5gc | 1 |