Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-312 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 42 | 41 | 0 |
▁▁▁▁▁▁▁▁▂▁▃▄▅█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 1 · 2026-05 4 · 2026-06 6 · 2026-07 10 · 2026-08 16
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-23655 | 6.5 | 58.6 | — | Microsoft ACI Confidential Containers Information Disclosure Vulnerability |
| CVE-2026-42151 | 7.5 | 28.4 | — | Prometheus Azure AD remote write OAuth client secret exposed via config API |
| CVE-2026-27877 | 6.5 | 23.6 | — | Public dashboards discloses all direct mode datasources |
| CVE-2026-31848 | 8.7 | 20.6 | — | Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+ |
| CVE-2025-44649 | 7.5 | 15.1 | — | — |
| CVE-2026-13380 | 9.0 | 14.7 | — | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses |
| CVE-2026-15721 | 9.8 | 14.3 | — | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HU… |
| CVE-2026-59244 | 6.5 | 14.1 | — | Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered T… |
| CVE-2026-68970 | 6.5 | 14.1 | — | Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Re… |
| CVE-2026-61928 | 5.5 | 11.6 | — | Windows Hello Tampering Vulnerability |
| CVE-2026-32842 | 7.1 | 11.2 | — | Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext |
| CVE-2026-20312 | 8.8 | 10.0 | — | Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities |
| CVE-2026-46622 | 8.1 | 9.8 | — | SolidInvoice: API tokens stored as plaintext in the database allowing full credential c… |
| CVE-2026-47702 | 9.1 | 9.7 | — | TypeBot API tokens stored in plaintext |
| CVE-2026-7163 | 6.1 | 9.4 | — | Assisted-service: assisted-service: authenticated users can gain administrative access … |
| CVE-2026-55885 | 6.8 | 7.2 | — | Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets |
| CVE-2026-65599 | 5.1 | 5.0 | — | n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header |
| CVE-2026-45040 | 5.3 | 4.9 | — | RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs… |
| CVE-2026-19391 | 6.5 | 4.8 | — | Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwor… |
| CVE-2026-55985 | 5.3 | 4.7 | — | Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information |
| Vendor | CVEs |
|---|---|
| red hat | 5 |
| apache | 2 |
| devolutions | 2 |
| microsoft | 2 |
| baptistearno | 1 |
| bilin software and informatics consultancy | 1 |
| bosch | 1 |
| cisco | 1 |
| cp plus | 1 |
| edimax technology co | 1 |
| fantomas42 | 1 |
| getgrav | 1 |
| grafana | 1 |
| ibm | 1 |
| jenkins project | 1 |