Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 118 | 113 | 6 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▆▆
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 22 · 2026-06 36 · 2026-07 25 · 2026-08 27
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-55591 | 9.8 | 99.9 | KEV | Fortinet FortiOS and FortiProxy |
| CVE-2026-23760 | 9.3 | 99.9 | KEV | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API |
| CVE-2023-20269 | 9.1 | 97.4 | KEV | Cisco Adaptive Security Appliance and Firepower Threat Defense |
| CVE-2026-18577 | 8.2 | 89.9 | KEV | Incomplete patch leads to administrative account takeover |
| CVE-2025-24472 | 8.1 | 88.5 | KEV | Fortinet FortiOS and FortiProxy |
| CVE-2026-18556 | 8.2 | 40.3 | KEV | Unauthenticated administrative account takeover |
| CVE-2026-10523 | 9.8 | 98.9 | — | — |
| CVE-2026-20079 | 10.0 | 98.4 | — | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vul… |
| CVE-2026-24207 | 9.8 | 83.8 | — | — |
| CVE-2026-53576 | 10.0 | 81.0 | — | Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass |
| CVE-2026-44575 | 7.5 | 73.7 | — | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes |
| CVE-2026-18574 | 9.3 | 59.8 | — | Authentication Bypass in Check Point Security Management Server |
| CVE-2026-48020 | 7.8 | 55.8 | — | Traefik StripPrefix Route-Level Auth Bypass via Path Normalization |
| CVE-2026-43945 | 8.9 | 55.7 | — | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection |
| CVE-2019-25763 | 9.3 | 53.7 | — | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass |
| CVE-2026-61884 | 9.3 | 49.0 | — | Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel |
| CVE-2026-35087 | 9.3 | 48.9 | — | Authentication Bypass in Slican telephone exchanges |
| CVE-2026-44574 | 8.1 | 47.8 | — | Next.js: Middleware / Proxy bypass through dynamic route parameter injection |
| CVE-2020-37255 | 8.7 | 47.4 | — | WordPress Time Capsule Plugin 1.21.16 Authentication Bypass |
| CVE-2026-35090 | 9.3 | 47.3 | — | Authentication Bypass in Slican telephone exchanges |