Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-359 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 23 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▂▁▁▂█▅▃
2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 10 · 2026-07 6 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-26192 | 8.2 | 72.4 | — | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-20834 | 4.6 | 51.8 | — | Windows Spoofing Vulnerability |
| CVE-2019-25762 | 8.7 | 43.1 | — | Joomla! Component JoomProject 1.1.3.2 Information Disclosure |
| CVE-2025-43496 | 7.5 | 40.1 | — | — |
| CVE-2026-56171 | 7.5 | 39.5 | — | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-0102 | 3.1 | 38.5 | — | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability |
| CVE-2026-50657 | 5.5 | 36.6 | — | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-48615 | 7.5 | 35.3 | — | — |
| CVE-2026-25699 | 6.1 | 34.0 | — | Apache Answer: Authorization Bypass in Timeline API |
| CVE-2026-49344 | 7.1 | 31.5 | — | Mercator has a Personal Identifiable Information Leak from Query Executor feature |
| CVE-2026-62328 | 8.7 | 30.3 | — | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints |
| CVE-2026-56124 | 8.7 | 29.8 | — | phpUploader < 2.0.2 Unauthenticated Database Exposure via index model |
| CVE-2026-55496 | 4.3 | 29.3 | — | Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because Se… |
| CVE-2026-48048 | 7.5 | 29.3 | — | XWiki Platform's Livetable results still allow reconstructing password hashes using 768… |
| CVE-2026-57960 | 8.3 | 27.0 | — | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id |
| CVE-2026-26237 | 6.6 | 25.1 | — | QuMagie |
| CVE-2026-58297 | 7.1 | 23.6 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-58296 | 7.1 | 23.0 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-54264 | 8.3 | 14.7 | — | Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker |
| CVE-2025-13477 | 7.1 | 13.3 | — | OTP Bypass in Digital Operation Services' WifiBurada |
| Vendor | CVEs |
|---|---|
| microsoft | 7 |
| apple | 2 |
| angular | 1 |
| apache | 1 |
| cloudreve | 1 |
| decolua | 1 |
| digital operations services | 1 |
| gitea | 1 |
| hellotalk | 1 |
| hieventsdev | 1 |
| joomboost | 1 |
| nodejs | 1 |
| qnap systems | 1 |
| qualcomm | 1 |
| shimosyan | 1 |