Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-347 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 139 | 133 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▅▇█
2025-09 0 · 2025-10 2 · 2025-11 0 · 2025-12 2 · 2026-01 1 · 2026-02 1 · 2026-03 6 · 2026-04 3 · 2026-05 8 · 2026-06 26 · 2026-07 41 · 2026-08 47
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-59718 | 9.1 | 99.1 | KEV | Fortinet Multiple Products |
| CVE-2026-48558 | 9.5 | 95.7 | KEV | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification |
| CVE-2025-59719 | 9.1 | 97.7 | — | — |
| CVE-2026-40372 | 9.1 | 95.6 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-10795 | 8.1 | 88.5 | — | UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication By… |
| CVE-2024-8698 | 7.7 | 79.5 | — | Keycloak-saml-core: improper verification of saml responses leading to privilege escala… |
| CVE-2026-54733 | 9.3 | 57.4 | — | moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endp… |
| CVE-2026-12263 | 8.8 | 50.2 | — | Authentication Bypass |
| CVE-2026-59243 | 9.8 | 49.8 | — | Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by d… |
| CVE-2026-5588 | 6.3 | 47.9 | — | PKIX draft CompositeVerifier accepts empty signature sequence as valid. |
| CVE-2026-10754 | 8.6 | 44.9 | — | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of c… |
| CVE-2026-27962 | 9.1 | 43.5 | — | Authlib JWS JWK Header Injection: Signature Verification Bypass |
| CVE-2025-33074 | 7.5 | 43.4 | — | Azure Functions Remote Code Execution Vulnerability |
| CVE-2026-33117 | 9.1 | 39.5 | — | Azure SDK for Java Security Feature Bypass Vulnerability |
| CVE-2026-33894 | 7.5 | 39.0 | — | Forge has signature forgery in RSA-PKCS due to ASN.1 extra field |
| CVE-2026-15265 | 9.4 | 38.4 | — | Tenable Agent Path Traversal Leading to Remote Code Execution |
| CVE-2026-50010 | 7.5 | 38.0 | — | Netty's wrapping plain trust manager silently disables hostname verification |
| CVE-2026-15013 | 9.8 | 37.5 | — | SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse'… |
| CVE-2026-28802 | 7.7 | 35.7 | — | Authlib: Setting `alg: none` and a blank signature appears to bypass signature verifica… |
| CVE-2026-9779 | 7.2 | 33.1 | — | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Rem… |
| Vendor | CVEs |
|---|---|
| microsoft | 9 |
| red hat | 9 |
| timlegge | 5 |
| corewcf | 4 |
| legion of the bouncy castle | 4 |
| sigstore | 4 |
| wolfssl | 4 |
| jfrog | 3 |
| siemens | 3 |
| symfony | 3 |
| apache | 2 |
| authlib | 2 |
| fortinet | 2 |
| go toolchain | 2 |
| golang.org/x/mod | 2 |