Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-345 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 149 | 144 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▇█
2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 11 · 2026-06 30 · 2026-07 48 · 2026-08 52
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-38831 | 7.8 | 99.9 | KEV | RARLAB WinRAR |
| CVE-2026-21527 | 6.5 | 94.1 | — | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-62869 | 8.8 | 34.6 | — | Azure Entra ID Spoofing Vulnerability |
| CVE-2025-27735 | 6.0 | 31.8 | — | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
| CVE-2026-71965 | 8.7 | 27.6 | — | CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature |
| CVE-2026-26007 | 8.2 | 27.3 | — | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves |
| CVE-2026-50195 | 5.6 | 26.3 | — | containerd: CRI checkpoint import allows local image tag poisoning |
| CVE-2026-47691 | 10.0 | 24.6 | — | Netty has Insufficient Bailiwick Validation for NS Records |
| CVE-2026-7792 | 5.3 | 22.8 | — | WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity vi… |
| CVE-2026-19127 | 6.5 | 21.2 | — | Insufficient verification of lifetime-deal redemption codes allows forgery of permanent… |
| CVE-2025-34337 | 8.7 | 19.6 | — | eGovFramework <= 4.3.1 Unauthenticated Encryption Oracle via Web Editor Image Upload En… |
| CVE-2026-56073 | 9.3 | 19.3 | — | Cap-go - OTP Bypass via Response Manipulation in Email Verification |
| CVE-2026-32597 | 7.5 | 19.1 | — | PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) |
| CVE-2026-63687 | 9.1 | 18.6 | — | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters |
| CVE-2026-55698 | 8.8 | 18.5 | — | pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc… |
| CVE-2026-65583 | 9.1 | 18.2 | — | Apache CXF: Self-issued ID token claims validation skipped |
| CVE-2026-3012 | 6.8 | 18.0 | — | Samba: group policy certificate enrollment uses http:// without validation |
| CVE-2026-47155 | 6.5 | 16.6 | — | vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weigh… |
| CVE-2026-45674 | 10.0 | 16.4 | — | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records |
| CVE-2024-12369 | 4.2 | 16.4 | — | Elytron-oidc-client: oidc authorization code injection |