Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-346 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 233 | 230 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▃
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 21 · 2026-06 77 · 2026-07 103 · 2026-08 28
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-53399 | 6.9 | 91.4 | — | — |
| CVE-2026-54069 | 9.2 | 47.2 | — | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist |
| CVE-2024-1249 | 7.4 | 37.4 | — | Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginif… |
| CVE-2026-57989 | 7.4 | 36.0 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-46409 | 9.6 | 29.5 | — | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution |
| CVE-2026-66318 | 8.1 | 29.3 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2025-71214 | 7.8 | 29.0 | — | — |
| CVE-2026-20643 | 5.4 | 28.6 | — | — |
| CVE-2026-6734 | 8.8 | 27.7 | — | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2025-71213 | 7.8 | 26.8 | — | — |
| CVE-2026-47691 | 10.0 | 24.6 | — | Netty has Insufficient Bailiwick Validation for NS Records |
| CVE-2026-59208 | 7.6 | 24.2 | — | n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution |
| CVE-2026-13793 | 6.5 | 22.9 | — | — |
| CVE-2026-13840 | 6.5 | 22.9 | — | — |
| CVE-2026-13913 | 6.5 | 22.9 | — | — |
| CVE-2026-42901 | 10.0 | 22.7 | — | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-71217 | 7.8 | 22.2 | — | — |
| CVE-2026-13826 | 6.5 | 21.6 | — | — |
| CVE-2026-13887 | 6.5 | 21.6 | — | — |
| CVE-2026-58169 | 7.7 | 21.1 | — | Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding… |
| Vendor | CVEs |
|---|---|
| 116 | |
| mozilla | 14 |
| microsoft | 10 |
| trend micro | 9 |
| red hat | 4 |
| guzzle | 3 |
| netty | 3 |
| synology | 3 |
| ankitects | 2 |
| apple | 2 |
| eclipse foundation | 2 |
| ibm | 2 |
| lightpanda-io | 2 |
| modelcontextprotocol | 2 |
| nlnet labs | 2 |