Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-319 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 39 | 37 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃█▄▂
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 19 · 2026-07 7 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21406 | 7.5 | 55.5 | — | Windows Printing Service Spoofing Vulnerability |
| CVE-2026-24212 | 9.8 | 48.6 | — | — |
| CVE-2026-15806 | 6.0 | 29.6 | — | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme… |
| CVE-2026-49486 | 7.5 | 22.2 | — | Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing P… |
| CVE-2026-3182 | 4.3 | 20.2 | — | Sensitive Data Exposure |
| CVE-2024-10973 | 5.7 | 19.7 | — | Keycloak: cli option for encrypted jgroups ignored |
| CVE-2026-48902 | 9.8 | 16.8 | — | Joomla! Core - [20260518] - Transport encryption downgrade for password and username re… |
| CVE-2026-45432 | 8.7 | 15.9 | — | Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models |
| CVE-2024-47269 | 4.9 | 14.1 | — | — |
| CVE-2026-11833 | 8.2 | 12.5 | — | — |
| CVE-2026-48978 | 2.1 | 11.6 | — | oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and… |
| CVE-2026-50034 | 7.1 | 11.4 | — | Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sen… |
| CVE-2026-25608 | 2.3 | 11.3 | — | Lack of traffic encryption in STER |
| CVE-2026-34346 | 5.5 | 10.5 | — | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability |
| CVE-2026-64742 | 6.5 | 9.7 | — | — |
| CVE-2026-43625 | 8.2 | 8.6 | — | CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect |
| CVE-2026-50200 | 7.5 | 8.4 | — | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-47255 | 8.2 | 7.6 | — | AgenticMail API/storage and outbound relay hardening |
| CVE-2026-53624 | 4.8 | 7.7 | — | Fiber: HSTS header never set in helmet middleware due to incorrect protocol check |
| CVE-2026-2671 | 2.3 | 6.9 | — | Mendi Neurofeedback Headset Bluetooth Low Energy cleartext transmission |
| Vendor | CVEs |
|---|---|
| ibm | 2 |
| microsoft | 2 |
| synology | 2 |
| agenticmail | 1 |
| apache | 1 |
| apollo pharmacy | 1 |
| apple | 1 |
| aws | 1 |
| centralny instytut ochrony pracy - państwowy instytut badawczy | 1 |
| cisco | 1 |
| denoland | 1 |
| djangoproject | 1 |
| edimax technology co | 1 |
| eidetic-labs | 1 |
| gofiber | 1 |