Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-276 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 58 | 49 | 0 |
▂▁▁▁▁▁▁▂▁▁▁▁▁▂▂▁▁▂▂▁▂▁▁▁▁▂▂▅██▇
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 7 · 2026-06 14 · 2026-07 14 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-38222 | 6.5 | 63.6 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2025-29801 | 7.8 | 60.6 | — | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability |
| CVE-2024-46695 | 4.4 | 42.6 | — | selinux,smack: don't bypass permissions check in inode_setsecctx hook |
| CVE-2026-17497 | 8.3 | 37.9 | — | NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python |
| CVE-2026-33590 | 8.5 | 37.7 | — | Insecure default permissions in Portainer CE |
| CVE-2026-49157 | 8.8 | 36.8 | — | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management… |
| CVE-2025-8031 | 9.8 | 36.1 | — | Incorrect URL stripping in CSP reports |
| CVE-2026-59119 | 7.3 | 28.8 | — | PowerShell Elevation of Privilege Vulnerability |
| CVE-2024-1488 | 7.3 | 24.9 | — | Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privileg… |
| CVE-2026-19893 | 2.3 | 21.2 | — | D-Link DIR-842 vsftpd vsftpd.conf default permission |
| CVE-2026-8487 | 7.5 | 20.5 | — | Incorrect default permissions vulnerability in Progress Software MOVEit Automation |
| CVE-2023-54366 | 8.7 | 20.3 | — | SurrealDB before 1.0.1 Insecure Default Table Permissions |
| CVE-2025-7195 | 6.4 | 12.8 | — | Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd |
| CVE-2026-48725 | 8.1 | 12.0 | — | Warp may allow terminal output to access the local clipboard through OSC 52 |
| CVE-2026-65940 | 6.8 | 11.7 | — | WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privil… |
| CVE-2016-20029 | 6.9 | 11.0 | — | ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability |
| CVE-2024-58356 | 2.3 | 9.8 | — | SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE |
| CVE-2026-19841 | 2.3 | 8.5 | — | TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission |
| CVE-2026-48935 | 3.3 | 8.4 | — | — |
| CVE-2025-57848 | 6.4 | 7.5 | — | Container-native-virtualization: privilege escalation via excessive /etc/passwd permiss… |
| Vendor | CVEs |
|---|---|
| red hat | 4 |
| microsoft | 3 |
| xen | 3 |
| amd | 2 |
| apple | 2 |
| bizerba se & co. kg | 2 |
| codesys | 2 |
| dell | 2 |
| otrs | 2 |
| progress | 2 |
| surrealdb | 2 |
| watchguard | 2 |
| absolute security | 1 |
| apache | 1 |
| aruba | 1 |