Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-295 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 135 | 133 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇▇█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 2 · 2026-05 21 · 2026-06 35 · 2026-07 32 · 2026-08 40
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50752 | 7.4 | 90.8 | — | Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 |
| CVE-2024-43550 | 7.4 | 62.9 | — | Windows Secure Channel Spoofing Vulnerability |
| CVE-2026-18129 | 8.1 | 56.0 | — | — |
| CVE-2026-11814 | 4.9 | 54.6 | — | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers |
| CVE-2026-21228 | 8.1 | 51.4 | — | Azure Local Remote Code Execution Vulnerability |
| CVE-2026-43869 | 7.3 | 47.6 | — | Apache Thrift: TSSLTransportFactory.java hostname verification |
| CVE-2026-27137 | 7.5 | 46.4 | — | Incorrect enforcement of email constraints in crypto/x509 |
| CVE-2026-42508 | 9.1 | 44.6 | — | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts |
| CVE-2026-8992 | 8.8 | 44.4 | — | — |
| CVE-2026-42011 | 7.4 | 39.2 | — | Gnutls: gnutls: security bypass due to incorrect name constraint handling |
| CVE-2026-9697 | 7.4 | 38.2 | — | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5… |
| CVE-2026-42013 | 8.2 | 35.5 | — | Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name |
| CVE-2026-42769 | 5.3 | 33.5 | — | Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| CVE-2026-63650 | 2.0 | 29.6 | — | — |
| CVE-2026-11564 | 9.1 | 29.6 | — | Native CA trust persist |
| CVE-2026-42012 | 7.1 | 28.6 | — | Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans |
| CVE-2026-59825 | 7.4 | 27.9 | — | Mastodon: Unwanted deactivation of SSL/TLS certificate verification |
| CVE-2026-12064 | 7.5 | 26.9 | — | proto-default skips SSH verification |
| CVE-2026-42790 | 7.6 | 26.9 | — | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif… |
| CVE-2026-58162 | 8.4 | 26.2 | — | Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates |
| Vendor | CVEs |
|---|---|
| wolfssl | 10 |
| red hat | 8 |
| apache | 6 |
| microsoft | 5 |
| dell | 4 |
| erlang | 4 |
| ibm | 4 |
| open ises | 4 |
| curl | 3 |
| ecovacs robotics | 3 |
| freerdp | 3 |
| canon | 2 |
| com.oviva.telematik | 2 |
| cyberark software, a palo alto networks company | 2 |
| fbeta-gmbh | 2 |