Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-285 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 279 | 269 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 3 · 2026-04 3 · 2026-05 22 · 2026-06 82 · 2026-07 111 · 2026-08 46
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-29794 | 8.8 | 91.4 | — | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-10580 | 9.8 | 86.1 | — | Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to A… |
| CVE-2026-49170 | 7.8 | 85.3 | — | Windows StateRepository API Server file Elevation of Privilege Vulnerability |
| CVE-2024-38231 | 7.5 | 77.7 | — | Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
| CVE-2026-33186 | 9.1 | 73.2 | — | gRPC-Go has an authorization bypass via missing leading slash in :path |
| CVE-2026-55956 | 6.5 | 72.7 | — | Apache Tomcat: Security constraints for default servlet ignored method |
| CVE-2024-38129 | 7.5 | 67.4 | — | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2024-43482 | 6.5 | 63.0 | — | Microsoft Outlook for iOS Information Disclosure Vulnerability |
| CVE-2026-54121 | 8.8 | 61.7 | — | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2025-30392 | 9.8 | 61.4 | — | Azure AI Bot Elevation of Privilege Vulnerability |
| CVE-2026-27823 | 8.7 | 60.9 | — | Remote Code Execution Vulnerability in EGroupware |
| CVE-2026-48579 | 7.5 | 60.5 | — | Microsoft Exchange Online Information Disclosure Vulnerability |
| CVE-2026-62835 | 7.5 | 59.3 | — | Azure Portal Information Disclosure Vulnerability |
| CVE-2026-64642 | 8.3 | 58.4 | — | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and singl… |
| CVE-2025-30390 | 9.9 | 57.5 | — | Azure ML Compute Elevation of Privilege Vulnerability |
| CVE-2026-32213 | 10.0 | 57.3 | — | Azure AI Foundry Elevation of Privilege Vulnerability |
| CVE-2026-58277 | 8.8 | 56.7 | — | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2025-30389 | 8.7 | 55.1 | — | Azure Bot Framework SDK Elevation of Privilege Vulnerability |
| CVE-2026-49877 | 8.1 | 53.1 | — | Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console |
| CVE-2026-28865 | 7.5 | 52.6 | — | — |
| Vendor | CVEs |
|---|---|
| microsoft | 33 |
| sourcecodester | 12 |
| capgo | 10 |
| eleveo | 10 |
| oracle | 10 |
| apache | 8 |
| apple | 7 |
| ibm | 7 |
| astrbotdevs | 6 |
| nextlevelbuilder | 6 |
| webkul | 5 |
| berriai | 4 |
| datacycle-engine | 4 |
| theonedev | 4 |
| better-auth | 3 |