Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-352 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 410 | 404 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇█▅
2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 2 · 2026-01 1 · 2026-02 0 · 2026-03 5 · 2026-04 3 · 2026-05 76 · 2026-06 111 · 2026-07 131 · 2026-08 77
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-62593 | 9.4 | 60.5 | KEV | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack |
| CVE-2026-14620 | 4.7 | 42.2 | — | webpack-dev-server vulnerable to cross-site request forgery via internal developer endp… |
| CVE-2024-21381 | 6.8 | 35.3 | — | Microsoft Azure Active Directory B2C Spoofing Vulnerability |
| CVE-2026-44613 | 6.1 | 32.0 | — | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling |
| CVE-2026-8174 | 5.7 | 30.4 | — | Cross-site Request Forgery |
| CVE-2026-46409 | 9.6 | 29.5 | — | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution |
| CVE-2026-60009 | 8.8 | 25.2 | — | — |
| CVE-2026-52100 | 7.5 | 24.1 | — | — |
| CVE-2026-43735 | 8.1 | 22.9 | — | — |
| CVE-2026-49471 | 8.3 | 21.7 | — | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory po… |
| CVE-2026-13826 | 6.5 | 21.6 | — | — |
| CVE-2026-13887 | 6.5 | 21.6 | — | — |
| CVE-2026-13946 | 4.3 | 20.7 | — | — |
| CVE-2026-13952 | 4.3 | 20.7 | — | — |
| CVE-2026-49871 | 2.1 | 18.0 | — | Apache APISIX: cas-auth login CSRF / session injection issue |
| CVE-2026-15070 | 8.8 | 17.8 | — | Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution … |
| CVE-2019-25729 | 9.3 | 17.7 | — | PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie |
| CVE-2026-15747 | 9.1 | 17.3 | — | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of t… |
| CVE-2026-13944 | 3.1 | 16.7 | — | — |
| CVE-2026-13963 | 3.1 | 16.7 | — | — |
| Vendor | CVEs |
|---|---|
| oracle | 40 |
| 24 | |
| concrete cms | 20 |
| jenkins project | 11 |
| regularlabs.com | 7 |
| admidio | 5 |
| cotonti | 5 |
| mybb | 5 |
| ibm | 4 |
| rahulbhangale | 4 |
| apache | 3 |
| budibase | 3 |
| misp | 3 |
| sourcecodester | 3 |
| drupal | 2 |