Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-294 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 41 | 41 | 0 |
▃▄█▆
2026-05 4 · 2026-06 8 · 2026-07 17 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-62911 | 8.0 | 50.9 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-11856 | 9.8 | 46.3 | — | cross-origin Digest auth state leak |
| CVE-2026-28564 | 9.8 | 36.9 | — | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials |
| CVE-2026-73683 | 9.2 | 36.9 | — | Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay |
| CVE-2026-8927 | 9.1 | 36.8 | — | env-set cross-proxy Digest auth state leak |
| CVE-2026-47341 | 6.3 | 36.0 | — | Apache APISIX: Session replay issue in hmac-auth |
| CVE-2026-16083 | 5.5 | 36.1 | — | Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay |
| CVE-2026-53431 | 9.1 | 34.6 | — | Boruta accepts expired JWT client assertions due to missing exp claim validation |
| CVE-2026-68079 | 9.8 | 34.4 | — | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay |
| CVE-2026-20779 | 7.1 | 33.2 | — | Gitea TOTP single-use enforcement defect allows OTP replay |
| CVE-2026-26232 | 9.1 | 31.2 | — | Gitea OAuth2 authorization codes lack expiry and reuse enforcement |
| CVE-2026-51597 | 9.1 | 30.5 | — | — |
| CVE-2026-57574 | 7.4 | 27.1 | — | Misskey: TOTP tokens can be reused |
| CVE-2026-17045 | 8.1 | 22.9 | — | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-9095 | 8.1 | 22.5 | — | CVE-2026-9095 |
| CVE-2026-9398 | 1.3 | 22.0 | — | Besen BS20 EV Charging Station BLE/WiFi authentication replay |
| CVE-2026-44946 | 9.5 | 21.7 | — | SAML Authentication Replay in Rancher |
| CVE-2026-73431 | 8.8 | 20.4 | — | Reusable Account Activation and Recovery Tokens Allow Repeated Account Takeover in vuln… |
| CVE-2026-54779 | 5.9 | 19.1 | — | CoreWCF: SAML token replay protection is inoperative |
| CVE-2023-33854 | 5.3 | 16.7 | — | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cl… |
| Vendor | CVEs |
|---|---|
| apache | 4 |
| hcl software | 3 |
| ibm | 3 |
| corewcf | 2 |
| curl | 2 |
| gitea | 2 |
| microsoft | 2 |
| zenhive | 2 |
| alps electric co | 1 |
| besen | 1 |
| casdoor | 1 |
| craftcms | 1 |
| craigjbass | 1 |
| indian motorcycle | 1 |
| laravel | 1 |