Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-280 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 20 | 0 |
▂▁▁▂▄▆█▄
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-20817 | 7.8 | 92.1 | — | Windows Error Reporting Service Elevation of Privilege Vulnerability |
| CVE-2026-2340 | 6.5 | 58.1 | — | Samba: vfs_worm does not block directory modification |
| CVE-2026-40371 | 8.8 | 47.5 | — | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-73239 | 6.5 | 27.4 | — | Apache Allura: Missing permission checks IDOR |
| CVE-2026-18860 | 8.7 | 23.1 | — | Velociraptor incorrect Org deletion permissions check |
| CVE-2026-41566 | 9.4 | 21.9 | — | Apache Kvrocks: Improper permission for the APPLYBATCH command |
| CVE-2026-62393 | 4.3 | 21.3 | — | Apache Kylin: Improper authorization in job information retrieval |
| CVE-2026-9792 | 6.5 | 19.0 | — | Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition |
| CVE-2026-10549 | 5.3 | 19.0 | — | Privilege escalation in Yandex Database |
| CVE-2026-58416 | 7.1 | 16.9 | — | Fork-PR Actions task can read a third private repository via the collaborative-owner br… |
| CVE-2026-11764 | 3.6 | 14.0 | — | Data exposed without proper permission |
| CVE-2026-27910 | 7.8 | 11.0 | — | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-54261 | 6.5 | 10.3 | — | Wagtail: Improper permission handling in image preview |
| CVE-2026-54259 | 4.3 | 5.9 | — | Wagtail: Improper restriction handling on Documents and Images chosen endpoints |
| CVE-2026-54262 | 4.3 | 5.9 | — | Wagtail: Pages translations can be created without page permissions when using simple_t… |
| CVE-2026-11804 | 5.2 | 4.7 | — | Program Module Vulnerability |
| CVE-2026-46054 | 7.1 | 2.5 | — | selinux: fix overlayfs mmap() and mprotect() access checks |
| CVE-2026-20463 | 6.7 | 1.5 | — | — |
| CVE-2026-45195 | 7.8 | 1.2 | — | GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted |
| CVE-2026-45196 | 7.8 | 1.2 | — | GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers f… |