Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-308 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
█▃▃
2026-06 3 · 2026-07 1 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-56022 | 6.9 | 43.9 | — | Webmin MFA bypass |
| CVE-2026-67611 | 8.6 | 25.9 | — | OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration |
| CVE-2026-15616 | 9.1 | 25.8 | — | Local MFA not enforced during SSO sign-in |
| CVE-2026-45749 | 8.1 | 25.4 | — | Termix's TOTP two-factor authentication can be disabled or bypassed using only the acco… |
| CVE-2024-27928 | 5.9 | 20.4 | — | Vantage6: 2FA can be circumvented with hacked email access |
| Vendor | CVEs |
|---|---|
| logto | 1 |
| openemr | 1 |
| termix-ssh | 1 |
| vantage6 | 1 |
| webmin | 1 |