Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-305 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 18 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▇▇██
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 4 · 2026-07 5 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-25555 | 9.3 | 77.1 | — | OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header |
| CVE-2026-19349 | 9.8 | 54.3 | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, fro… |
| CVE-2023-4501 | 9.8 | 47.1 | — | Authentication bypass in OpenText (Micro Focus) Enterprise Server |
| CVE-2026-41052 | 9.4 | 34.7 | — | Rancher Privilege Escalation from Project Owner to Host |
| CVE-2026-6266 | 8.3 | 33.1 | — | Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified e… |
| CVE-2026-9798 | 4.3 | 28.0 | — | Keycloak: keycloak: brute-force protection bypass in ciba flow |
| CVE-2025-4994 | 8.7 | 26.1 | — | Authentication Bypass for SafeLine SL6 and SL6+ |
| CVE-2026-9047 | 7.6 | 24.7 | — | — |
| CVE-2026-1621 | 5.3 | 21.2 | — | Register Bypass in Universal Sotware's E-Municipality |
| CVE-2026-10539 | 9.5 | 19.0 | — | Unauthenticated command injection in Control-M/Server communication command |
| CVE-2026-62427 | 8.8 | 16.6 | — | sysctl and platform-op locks open to abuse |
| CVE-2026-19292 | 8.8 | 13.7 | — | Bluetooth re-pairing with legitimate device can use lower security level |
| CVE-2026-35159 | 5.3 | 8.6 | — | — |
| CVE-2026-41054 | 7.8 | 8.4 | — | Missing exit out of permission check in haveged could lead to root exploit |
| CVE-2026-65935 | 7.6 | 7.8 | — | Bypassing passkey entry in legacy pairing |
| CVE-2026-9571 | 6.5 | 7.2 | — | Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh … |
| CVE-2026-9597 | 5.4 | 3.9 | — | Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API… |
| CVE-2025-7064 | 5.6 | 1.9 | — | Freelance Security Lock – Access to Windows OS |
| CVE-2025-14600 | 9.3 | — | — | Admin Account Takeover via Path Traversal in vsDesk |
| Vendor | CVEs |
|---|---|
| mattermost | 2 |
| red hat | 2 |
| silabs.com | 2 |
| suse | 2 |
| abb | 1 |
| bmc | 1 |
| dell | 1 |
| devolutions | 1 |
| openbullet | 1 |
| opentext | 1 |
| safeline | 1 |
| universal software | 1 |
| vsdesk | 1 |
| xen | 1 |