Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-425 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 11 | 10 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▄▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 2 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34028 | 6.9 | 33.1 | — | Unauthenticated direct access to web data in Wertheim SafeController Software exposes f… |
| CVE-2023-4018 | 4.3 | 32.8 | — | Direct Request ('Forced Browsing') in GitLab |
| CVE-2026-10521 | 8.6 | 24.1 | — | Authenticated unintended access to critical program parameters |
| CVE-2026-19903 | 5.5 | 23.9 | — | SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access |
| CVE-2026-11986 | 4.9 | 22.7 | — | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk… |
| CVE-2026-13533 | 5.5 | 21.2 | — | agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access |
| CVE-2026-60011 | 6.9 | 14.3 | — | — |
| CVE-2026-8205 | 6.3 | 11.7 | — | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block si… |
| CVE-2026-9610 | 5.3 | 8.9 | — | Multiple Vulnerabilities in IBM Datacap |
| CVE-2024-23573 | 3.7 | 5.2 | — | — |
| CVE-2026-21760 | 4.6 | 4.6 | — | Unauthorized Access to Admin Functionality via Forced Browsing |
| Vendor | CVEs |
|---|---|
| hclsoftware | 2 |
| agentejo | 1 |
| concrete cms | 1 |
| gitlab | 1 |
| ibm | 1 |
| mb connect line | 1 |
| red hat | 1 |
| sharp | 1 |
| sourcecodester | 1 |
| toshiba tec | 1 |
| wertheim | 1 |