Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-250 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 50 | 43 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂█▇▇
2025-09 2 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 15 · 2026-07 12 · 2026-08 13
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-7387 | 9.1 | 81.9 | — | Openshift/builder: path traversal allows command injection in privileged buildcontainer… |
| CVE-2024-43583 | 7.8 | 69.1 | — | Winlogon Elevation of Privilege Vulnerability |
| CVE-2023-5207 | 8.2 | 62.8 | — | Execution with Unnecessary Privileges in GitLab |
| CVE-2026-59133 | 8.8 | 57.5 | — | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
| CVE-2026-42833 | 9.1 | 52.1 | — | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2025-57119 | 9.8 | 44.1 | — | — |
| CVE-2026-18669 | 8.8 | 41.5 | — | IBM i is Affected By A Privilege Escalation Vulnerability [] |
| CVE-2024-5042 | 6.6 | 41.0 | — | Submariner-operator: rbac permissions can allow for the spread of node compromises |
| CVE-2026-48584 | 8.8 | 40.8 | — | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-18982 | 8.8 | 40.5 | — | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit… |
| CVE-2026-17110 | 8.8 | 40.3 | — | IBM i is Affected By Multiple Vulnerabilities in SQL |
| CVE-2026-44477 | 9.4 | 39.5 | — | CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and… |
| CVE-2026-18608 | 8.7 | 36.4 | — | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflo… |
| CVE-2026-18949 | 8.8 | 34.7 | — | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac … |
| CVE-2026-46618 | 6.9 | 29.6 | — | Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.comman… |
| CVE-2026-46617 | 8.7 | 27.7 | — | Fission runtime pods automount the fission-fetcher service-account token into the user … |
| CVE-2026-72508 | 9.9 | 27.4 | — | Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ser… |
| CVE-2026-47190 | 4.4 | 26.3 | — | IPAM controller service account granted unnecessary full access to Secrets |
| CVE-2026-10843 | 7.2 | 25.8 | — | Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wid… |
| CVE-2025-56557 | 9.1 | 24.0 | — | — |
| Vendor | CVEs |
|---|---|
| red hat | 11 |
| xen | 5 |
| fission | 4 |
| ibm | 4 |
| microsoft | 4 |
| canonical | 2 |
| 2 | |
| 0x5t4l1n | 1 |
| acronis | 1 |
| analog way | 1 |
| broadcom | 1 |
| cloudnative-pg | 1 |
| daytonaio | 1 |
| enterprisedb | 1 |
| forcepoint | 1 |