Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-358 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 18 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁█▅▅▁
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 8 · 2026-06 5 · 2026-07 5 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50628 | 9.8 | 50.1 | — | Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control |
| CVE-2023-4501 | 9.8 | 47.1 | — | Authentication bypass in OpenText (Micro Focus) Enterprise Server |
| CVE-2026-45109 | 7.5 | 44.6 | — | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes |
| CVE-2026-40597 | 7.6 | 40.7 | — | MantisBT has a Content Security Policy bypass via attachments |
| CVE-2024-55599 | 4.9 | 27.6 | — | — |
| CVE-2026-48797 | 9.3 | 25.4 | — | Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication |
| CVE-2026-57915 | 7.3 | 25.0 | — | Apache Kerby: Kerberos Pre-Authentication Bypass |
| CVE-2026-65058 | 5.9 | 20.5 | — | Trezor Safe improper security check in on-device display |
| CVE-2026-42081 | 7.1 | 18.9 | — | free5GC: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-49783 | 7.8 | 17.6 | — | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-12577 | 8.7 | 17.0 | — | DVP80ES3 Improperly Implemented Security Check for Standard vulnerability |
| CVE-2026-42082 | 5.4 | 16.8 | — | free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover |
| CVE-2026-46582 | 3.7 | 8.0 | — | A wildcard replay, as another piece of data, triggers poisoning in the serve expired re… |
| CVE-2026-11127 | 6.5 | 6.6 | — | — |
| CVE-2026-44473 | 7.1 | 6.3 | — | Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse |
| CVE-2026-11122 | 6.1 | 5.6 | — | — |
| CVE-2026-44475 | 6.1 | 4.5 | — | Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-28914 | 5.5 | 4.6 | — | — |
| CVE-2026-44474 | 3.7 | 3.4 | — | Ella Core: Handover failures during concurrent Security Mode Command |
| CVE-2026-54431 | 5.1 | 2.9 | — | Improper Data Validation in liboauth2 |
| Vendor | CVEs |
|---|---|
| ellanetworks | 3 |
| apache | 2 |
| free5gc | 2 |
| 2 | |
| apple | 1 |
| deltaww | 1 |
| fortinet | 1 |
| mantisbt | 1 |
| mcp-tool-shop-org | 1 |
| microsoft | 1 |
| nlnet labs | 1 |
| openidc | 1 |
| opentext | 1 |
| trezor | 1 |
| vercel | 1 |