Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-23 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 83 | 77 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█▃
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 14 · 2026-06 16 · 2026-07 34 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34926 | 6.7 | 95.9 | KEV | Trend Micro Apex One |
| CVE-2024-43454 | 7.1 | 97.5 | — | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| CVE-2026-23734 | 9.3 | 97.2 | — | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when us… |
| CVE-2023-35359 | 7.8 | 95.2 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-38258 | 7.5 | 91.1 | — | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
| CVE-2023-38185 | 8.8 | 84.6 | — | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-54066 | 7.5 | 77.9 | — | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary… |
| CVE-2026-14903 | 6.5 | 61.3 | — | — |
| CVE-2026-16053 | 8.5 | 59.8 | — | Path Traversal |
| CVE-2026-56196 | 8.8 | 58.6 | — | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-52813 | 10.0 | 57.5 | — | Gogs: Path Traversal in organization name results in RCE through Git hooks |
| CVE-2026-8023 | 7.5 | 57.2 | — | Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthen… |
| CVE-2026-62837 | 6.5 | 55.7 | — | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-51026 | 6.5 | 55.2 | — | — |
| CVE-2026-61343 | 8.6 | 55.0 | — | LibreBooking path traversal |
| CVE-2026-49290 | 7.6 | 54.8 | — | Slopsmith has path traversal in archive extractors that allows arbitrary file write → p… |
| CVE-2026-47287 | 6.5 | 53.3 | — | Visual Studio Code Tampering Vulnerability |
| CVE-2026-70337 | 8.8 | 52.4 | — | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-8134 | 9.4 | 51.8 | — | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp… |
| CVE-2026-40400 | 8.0 | 50.4 | — | Windows PowerShell Remote Code Execution Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 19 |
| suse | 3 |
| waterfall | 3 |
| apache | 2 |
| erlang | 2 |
| interinfo | 2 |
| jovancoding | 2 |
| openbsd | 2 |
| siyuan-note | 2 |
| allegroai | 1 |
| aws | 1 |
| byrongamatos | 1 |
| canonical | 1 |
| chimpstudio | 1 |
| concrete cms | 1 |