Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-266 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 243 | 237 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▃█▅▅
2025-09 0 · 2025-10 1 · 2025-11 2 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 24 · 2026-06 101 · 2026-07 51 · 2026-08 58
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48172 | 10.0 | 97.1 | KEV | LiteSpeed cPanel Plugin |
| CVE-2025-41115 | 10.0 | 96.8 | — | Incorrect privilege assignment |
| CVE-2025-34112 | 10.0 | 79.1 | — | Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE |
| CVE-2026-44173 | 5.3 | 47.0 | — | MariaDB: FILE privilege was not checked for subqueries in the FROM clause |
| CVE-2025-53744 | 6.8 | 46.7 | — | — |
| CVE-2026-20804 | 7.7 | 41.8 | — | Windows Hello Tampering Vulnerability |
| CVE-2026-49060 | 9.8 | 41.6 | — | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vuln… |
| CVE-2026-11492 | 2.1 | 41.4 | — | D-Link DIR-823G vsftpd vsftpd.conf least privilege violation |
| CVE-2026-20852 | 7.7 | 40.8 | — | Windows Hello Tampering Vulnerability |
| CVE-2026-9397 | 8.2 | 37.9 | — | Besen BS20 EV Charging Station OTA Update Installation improper authorization |
| CVE-2025-69179 | 9.8 | 37.6 | — | WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalation vulnera… |
| CVE-2026-56251 | 7.0 | 37.1 | — | Capgo - Privilege Escalation via Broken Row Level Security in org_users |
| CVE-2026-15270 | 6.8 | 37.0 | — | D-link DIR-823G Web boa.conf least privilege violation |
| CVE-2026-54807 | 9.8 | 36.6 | — | WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vuln… |
| CVE-2026-11497 | 5.5 | 36.2 | — | D-Link DCS-5615 Boa Webserver boa.conf least privilege violation |
| CVE-2026-15218 | 7.9 | 35.9 | — | Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts… |
| CVE-2026-48889 | 8.8 | 34.5 | — | WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability |
| CVE-2026-15271 | 7.7 | 34.1 | — | TOTOLINK EX200 Web boa.conf least privilege violation |
| CVE-2026-11555 | 2.9 | 33.9 | — | D-Link DGS-1100-08PD Web boa.conf least privilege violation |
| CVE-2026-12289 | 8.8 | 32.9 | — | Privilege escalation in the Graphics: WebRender component |
| Vendor | CVEs |
|---|---|
| sourcecodester | 14 |
| red hat | 12 |
| eleveo | 10 |
| d-link | 5 |
| nextlevelbuilder | 4 |
| theonedev | 4 |
| totolink | 4 |
| aomei | 3 |
| berriai | 3 |
| microsoft | 3 |
| nanocoai | 3 |
| nousresearch | 3 |
| openclaw | 3 |
| capgo | 2 |
| cosmicstack-labs | 2 |