Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-36 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 19 | 1 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▆▃▇█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-20250 | 7.8 | 99.9 | KEV | RARLAB WinRAR |
| CVE-2026-49290 | 7.6 | 54.8 | — | Slopsmith has path traversal in archive extractors that allows arbitrary file write → p… |
| CVE-2026-20834 | 4.6 | 51.8 | — | Windows Spoofing Vulnerability |
| CVE-2026-32175 | 4.3 | 50.8 | — | .NET Core Tampering Vulnerability |
| CVE-2026-10044 | 8.2 | 46.1 | — | ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/ |
| CVE-2026-15302 | 5.3 | 42.7 | — | ARMember <= 4.0.27 - Directory Traversal via X-FILENAME |
| CVE-2026-32997 | 8.6 | 41.6 | — | — |
| CVE-2026-61891 | 7.5 | 37.7 | — | — |
| CVE-2026-57211 | 10.0 | 35.9 | — | RabbitMQ: UNC SSRF affecting the management UI on Windows |
| CVE-2026-47606 | 6.5 | 34.2 | — | — |
| CVE-2026-10075 | 6.9 | 32.0 | — | Interinfo|DreamMaker - Path Traversal |
| CVE-2026-13189 | 7.5 | 29.3 | — | SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET … |
| CVE-2026-26337 | 8.8 | 29.0 | — | Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and … |
| CVE-2026-13346 | 5.6 | 27.9 | — | pip absolute path traversal during download from malicious package indexes |
| CVE-2026-58300 | 5.5 | 26.8 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-53698 | 6.5 | 25.7 | — | — |
| CVE-2026-54202 | 8.5 | 23.0 | — | TeamDavid: Path Traversal in the archive creation functionality |
| CVE-2026-47243 | 9.2 | 8.0 | — | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs |
| CVE-2026-46345 | 8.4 | 5.5 | — | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal |
| CVE-2026-47630 | 5.5 | 3.9 | — | — |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| nvidia | 2 |
| byrongamatos | 1 |
| check point | 1 |
| eclipse foundation | 1 |
| hyland | 1 |
| interinfo | 1 |
| kata-containers | 1 |
| oscal-compass | 1 |
| progress | 1 |
| python packaging authority | 1 |
| rabbitmq | 1 |
| reputeinfosystems | 1 |
| silverpeas | 1 |
| tobit laboratories | 1 |