Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-303 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 16 | 0 |
▂▁▄▇█▇
2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-41103 | 9.1 | 92.0 | — | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability |
| CVE-2026-59309 | 9.8 | 51.9 | — | vCenter authentication-bypass vulnerability |
| CVE-2026-12773 | 5.5 | 46.6 | — | BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication |
| CVE-2026-47300 | 8.8 | 42.4 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50360 | 8.8 | 42.4 | — | Windows SMB Server Elevation of Privilege Vulnerability |
| CVE-2026-11430 | 6.9 | 41.1 | — | Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit |
| CVE-2026-46595 | 10.0 | 41.0 | — | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh |
| CVE-2026-29515 | 9.3 | 39.6 | — | MiCode FileExplorer SwiFTP Server Authentication Bypass |
| CVE-2026-10050 | 8.7 | 38.9 | — | Digest authentication lossy encoding |
| CVE-2026-41053 | 8.8 | 37.8 | — | Over-inclusive team membership expansion in GitHub App authentication provider for Rancher |
| CVE-2026-50627 | 9.1 | 37.2 | — | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator |
| CVE-2026-57852 | 6.3 | 35.6 | — | Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check |
| CVE-2026-49467 | 8.8 | 34.5 | — | TOTP enrollment hijack: password gate skipped due to unawaited promise |
| CVE-2026-66411 | 6.9 | 32.4 | — | — |
| CVE-2026-46389 | 9.8 | 27.2 | — | UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretA… |
| CVE-2026-66028 | 7.1 | 25.0 | — | Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| trilby media | 2 |
| apache | 1 |
| berriai | 1 |
| creativeitem | 1 |
| defenseunicorns | 1 |
| eclipse foundation | 1 |
| ecovacs robotics | 1 |
| golang.org/x/crypto | 1 |
| micode | 1 |
| smp46 | 1 |
| suse | 1 |
| vmware | 1 |