Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1805 | 1771 | 6 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 8 · 2026-02 7 · 2026-03 2 · 2026-04 11 · 2026-05 80 · 2026-06 363 · 2026-07 901 · 2026-08 399
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2012-4681 | 9.8 | 99.9 | KEV | Oracle Java SE |
| CVE-2012-1723 | 9.8 | 99.8 | KEV | Oracle Java SE |
| CVE-2026-35616 | 9.8 | 99.8 | KEV | Fortinet FortiClient EMS |
| CVE-2026-34908 | 10.0 | 99.7 | KEV | Ubiquiti UniFi OS |
| CVE-2026-48907 | 10.0 | 99.3 | KEV | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for… |
| CVE-2019-11634 | 9.8 | 94.3 | KEV | Citrix Workspace Application and Receiver for Windows |
| CVE-2026-20896 | 9.8 | 98.2 | — | Gitea Docker image trusts spoofable reverse-proxy headers by default |
| CVE-2026-49049 | 7.5 | 98.0 | — | Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler |
| CVE-2026-20843 | 7.8 | 88.1 | — | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
| CVE-2026-66804 | 7.8 | 87.9 | — | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
| CVE-2026-49805 | 7.0 | 87.5 | — | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-21238 | 7.8 | 87.3 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2025-27738 | 6.5 | 87.0 | — | Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
| CVE-2025-21197 | 6.5 | 86.0 | — | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-50351 | 7.8 | 85.3 | — | Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability |
| CVE-2026-50423 | 7.8 | 84.3 | — | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-27914 | 7.8 | 84.0 | — | Microsoft Management Console Elevation of Privilege Vulnerability |
| CVE-2026-50746 | 10.0 | 83.5 | — | — |
| CVE-2025-29810 | 7.5 | 82.8 | — | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-39364 | 8.2 | 80.2 | — | Vite has a `server.fs.deny` bypass with queries |
| Vendor | CVEs |
|---|---|
| oracle | 1102 |
| microsoft | 98 |
| 57 | |
| gitea | 29 |
| apple | 22 |
| joomla! project | 16 |
| sourcecodester | 14 |
| red hat | 13 |
| dell | 12 |
| regularlabs.com | 11 |
| ubiquiti | 11 |
| fission | 7 |
| capgo | 6 |
| d-link | 6 |
| grafana | 6 |