Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-214
Weakness type CWE-214 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 15 | 0 |
Monthly trend
▂▁▁▁▅█▇▁
2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 6 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33247 | 5.3 | 43.3 | — | NATS credentials are exposed in monitoring port via command-line argv |
| CVE-2026-74873 | 8.7 | 22.2 | — | openssl_encrypt before 1.4.0 Password Exposure via CLI Argument |
| CVE-2026-76054 | 7.1 | 7.2 | — | — |
| CVE-2026-65088 | 5.5 | 5.6 | — | — |
| CVE-2026-81684 | 6.9 | 5.3 | — | openssl_encrypt before 1.4.9 Information Disclosure via Command Line |
| CVE-2026-12139 | 5.5 | 4.1 | — | Tanium addressed an information disclosure vulnerability in Connect. |
| CVE-2026-12250 | 7.9 | 3.8 | — | Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner |
| CVE-2026-92768 | 5.5 | 3.5 | — | Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments |
| CVE-2026-80158 | 5.5 | 3.3 | — | Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_… |
| CVE-2026-9494 | 5.5 | 3.3 | — | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process… |
| CVE-2026-18915 | 5.0 | 3.2 | — | Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-o… |
| CVE-2026-92745 | 5.0 | 3.0 | — | Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via pr… |
| CVE-2026-92747 | 5.0 | 3.0 | — | Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via js… |
| CVE-2026-61670 | 6.5 | 1.4 | — | microsandbox: Secret values exposed in world-readable process arguments |
| CVE-2026-102371 | 5.7 | 1.1 | — | wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 4 |
| canonical | 2 |
| jahlives | 2 |
| black duck | 1 |
| nats-io | 1 |
| nvidia | 1 |
| superradcompany | 1 |
| tanium | 1 |
| tubitak bilgem software technologies research institute | 1 |
| tübi̇tak bi̇lgem software technologies research institute | 1 |