Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-302 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
█▆▆
2026-06 3 · 2026-07 2 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47303 | 8.8 | 51.6 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50528 | 8.2 | 43.7 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-5423 | 8.2 | 26.5 | — | Subscription Authentication Bypass via Unverified connectionParams.jwt |
| CVE-2026-13267 | 8.1 | 16.4 | — | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security… |
| CVE-2026-48781 | 9.9 | 11.4 | — | Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery |
| CVE-2026-48117 | 6.8 | 8.3 | — | DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account… |
| CVE-2026-34460 | 5.4 | 1.7 | — | NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swap… |