Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-324 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 3 | 3 | 0 |
███
2026-06 1 · 2026-07 1 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-39923 | 9.2 | 18.0 | — | Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset |
| CVE-2026-52809 | 6.8 | 4.8 | — | Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CO… |
| CVE-2026-54787 | 3.1 | 0.5 | — | sigstore-go fails to check signature timestamps against a signing key's validity period |