Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-326 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 17 | 0 |
▂▁▁▁▁▁▂▁▂▃█▄
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 9 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-65777 | 5.3 | 21.3 | — | Active Directory Security Feature Bypass Vulnerability |
| CVE-2026-45363 | 9.1 | 15.6 | — | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-9201 | 8.8 | 14.4 | — | Langflow OSS is affected by arbitrary code execution in component generation, validatio… |
| CVE-2026-7830 | 7.4 | 12.8 | — | UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credent… |
| CVE-2026-8878 | 7.5 | 11.7 | — | CVE-2026-8878 |
| CVE-2026-74889 | 9.3 | 10.4 | — | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF |
| CVE-2025-63579 | 7.5 | 10.1 | — | — |
| CVE-2024-23564 | 9.1 | 8.8 | — | — |
| CVE-2026-59651 | 7.1 | 7.2 | — | BKS keystore accepts legacy version with 16-bit integrity MAC key |
| CVE-2026-28377 | 7.5 | 5.2 | — | S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) |
| CVE-2026-49852 | 8.7 | 4.1 | — | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of… |
| CVE-2026-4648 | 6.8 | 2.0 | — | Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands |
| CVE-2026-35146 | 6.3 | 1.9 | — | HCL DFXServer is affected by an Unencrypted Communication vulnerability. |
| CVE-2026-45787 | 6.0 | 1.2 | — | electerm's encrypt method not safe enough |
| CVE-2025-39889 | 8.1 | 0.5 | — | Bluetooth: l2cap: Check encryption key size on incoming connection |
| CVE-2026-50044 | 7.6 | 0.3 | — | Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs |
| CVE-2026-41860 | 7.1 | 0.1 | — | — |
| CVE-2026-14868 | 8.4 | 0.0 | — | Weak encryption mechanism for User directory |
| Vendor | CVEs |
|---|---|
| arcinfo | 1 |
| authlib | 1 |
| casfid servicios tecnológicos | 1 |
| cloud foundry foundation | 1 |
| electerm | 1 |
| grafana | 1 |
| hcl software | 1 |
| hclsoftware | 1 |
| ibm | 1 |
| jahlives | 1 |
| jwt | 1 |
| legion of the bouncy castle | 1 |
| linux | 1 |
| microsoft | 1 |
| pronetiqs | 1 |