Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-304 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
▆▆█
2026-06 2 · 2026-07 2 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55957 | 7.3 | 85.7 | — | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind |
| CVE-2026-61466 | 9.1 | 36.8 | — | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation |
| CVE-2026-49467 | 8.8 | 34.5 | — | TOTP enrollment hijack: password gate skipped due to unawaited promise |
| CVE-2026-67351 | 8.7 | 30.3 | — | Serendipity < 2.6.1 Authentication Bypass via Username Collision |
| CVE-2026-57915 | 7.3 | 25.0 | — | Apache Kerby: Kerberos Pre-Authentication Bypass |
| CVE-2026-61143 | 6.4 | 14.0 | — | — |
| CVE-2026-76207 | 8.6 | — | — | phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie |