Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 9 | 0 |
▃▁▁▁▁▃█▆▃
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 4 · 2026-07 3 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48618 | 6.5 | 87.2 | — | — |
| CVE-2026-50627 | 9.1 | 37.2 | — | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator |
| CVE-2026-56091 | 8.2 | 35.5 | — | Apache Shiro: Authentication bypass in Guice-Web integration |
| CVE-2026-8457 | 9.8 | 33.4 | — | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged … |
| CVE-2025-14777 | 6.0 | 28.2 | — | Keycloak: keycloak idor in realm client creating/deleting |
| CVE-2026-10842 | 7.5 | 23.8 | — | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected … |
| CVE-2026-53622 | 7.8 | 21.5 | — | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case… |
| CVE-2026-55075 | 7.4 | 21.1 | — | Coder vulnerable to OIDC account takeover via email-based user matching and email_verif… |
| CVE-2026-9701 | 9.8 | 20.8 | — | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escal… |
| CVE-2026-43617 | 6.3 | 20.7 | — | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution |