Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-307 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 58 | 54 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▆█
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 13 · 2026-07 15 · 2026-08 20
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-21709 | 9.8 | 79.0 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-44596 | 9.8 | 75.7 | — | Yamcs: No Rate Limiting on Authentication Endpoint |
| CVE-2021-29023 | 5.3 | 64.1 | — | — |
| CVE-2025-23368 | 8.1 | 55.4 | — | Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli |
| CVE-2026-8793 | 6.9 | 49.7 | — | PaperCut NG/MF: Insufficient brute-force protection |
| CVE-2026-8760 | 9.8 | 46.9 | — | Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force |
| CVE-2026-65948 | 7.3 | 45.7 | — | Apache Ranger: UnixAuth lacks brute-force protection |
| CVE-2026-56450 | 5.1 | 45.0 | — | AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Au… |
| CVE-2026-75773 | 2.9 | 42.3 | — | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication |
| CVE-2026-19898 | 2.9 | 39.7 | — | VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent… |
| CVE-2026-47203 | 2.9 | 37.8 | — | Authelia Missing Username Canonicalization in Basic Auth (LDAP) |
| CVE-2026-73056 | 9.3 | 37.6 | — | SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token |
| CVE-2026-3329 | 8.7 | 37.5 | — | Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-50176 | 8.7 | 35.9 | — | EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-73046 | 9.3 | 35.7 | — | SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
| CVE-2026-19297 | 9.1 | 35.0 | — | Insufficient Authentication Brute Force Protection on Login Endpoint |
| CVE-2026-10216 | 2.9 | 34.0 | — | unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication |
| CVE-2026-42952 | 8.7 | 33.7 | — | Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Exc… |
| CVE-2026-19895 | 2.9 | 33.6 | — | opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive auth… |
| CVE-2026-48071 | 5.8 | 31.2 | — | OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cros… |
| Vendor | CVEs |
|---|---|
| siyuan-note | 4 |
| drupal | 2 |
| open-reception | 2 |
| thorsten | 2 |
| @fastify/rate-limit | 1 |
| ail project | 1 |
| akinsoft | 1 |
| alextselegidis | 1 |
| apache | 1 |
| authelia | 1 |
| başbelen group food cafe businesses industry and trade ltd. co | 1 |
| better-auth | 1 |
| capgo | 1 |
| cp-plus | 1 |
| datacycle-engine | 1 |