Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-306 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 731 | 714 | 11 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▃
2025-09 0 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 4 · 2026-02 1 · 2026-03 3 · 2026-04 7 · 2026-05 41 · 2026-06 165 · 2026-07 390 · 2026-08 103
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-10271 | 7.5 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2024-0012 | 9.3 | 100.0 | KEV | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) |
| CVE-2026-41940 | 9.3 | 99.9 | KEV | WebPros cPanel and WHM Authentication Bypass via Login Flow |
| CVE-2026-20253 | 9.8 | 99.9 | KEV | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service … |
| CVE-2026-35273 | 9.8 | 99.9 | KEV | Oracle PeopleSoft Enterprise PeopleTools |
| CVE-2026-24423 | 9.3 | 99.7 | KEV | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API |
| CVE-2024-51567 | 9.8 | 99.7 | KEV | CyberPersons CyberPanel |
| CVE-2023-28461 | 9.8 | 99.3 | KEV | Array Networks AG/vxAG ArrayOS |
| CVE-2026-56164 | 9.8 | 97.5 | KEV | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2019-5591 | 6.5 | 97.0 | KEV | Fortinet FortiOS |
| CVE-2026-46817 | 9.8 | 96.1 | KEV | Oracle E-Business Suite |
| CVE-2026-8732 | 9.8 | 97.1 | — | WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account C… |
| CVE-2026-55450 | 9.3 | 95.7 | — | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
| CVE-2026-27446 | 9.3 | 95.2 | — | Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation |
| CVE-2026-62241 | 9.3 | 93.2 | — | clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery |
| CVE-2025-71257 | 6.9 | 91.8 | — | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass |
| CVE-2026-50507 | 6.8 | 91.6 | — | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2024-27890 | 7.2 | 90.6 | — | On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request… |
| CVE-2026-67208 | 9.3 | 90.2 | — | Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console |
| CVE-2026-56782 | 9.3 | 87.7 | — | Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints |
| Vendor | CVEs |
|---|---|
| oracle | 334 |
| microsoft | 28 |
| ibm | 9 |
| red hat | 9 |
| apache | 7 |
| fossbilling | 6 |
| decolua | 5 |
| free5gc | 5 |
| capgo | 4 |
| jetbrains | 4 |
| nasa-ammos | 4 |
| altium | 3 |
| arcadedata | 3 |
| eclipse foundation | 3 |
| gladinet | 3 |