Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-426 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 50 | 44 | 0 |
▂▁▁▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▂▂▁▂▃█▇▇
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-30100 | 7.8 | 65.3 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2025-27743 | 7.8 | 55.1 | — | Microsoft System Center Elevation of Privilege Vulnerability |
| CVE-2024-35260 | 9.8 | 54.4 | — | Microsoft Dataverse Remote Code Execution Vulnerability |
| CVE-2024-43616 | 7.8 | 52.9 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2023-36898 | 7.8 | 50.9 | — | Tablet Windows User Interface Application Core Remote Code Execution Vulnerability |
| CVE-2026-20943 | 7.0 | 48.5 | — | Microsoft Office Click-To-Run Remote Code Execution Vulnerability |
| CVE-2026-63093 | 8.7 | 44.0 | — | Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace |
| CVE-2024-43576 | 7.8 | 40.4 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44477 | 9.4 | 39.5 | — | CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and… |
| CVE-2026-42830 | 6.5 | 39.2 | — | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability |
| CVE-2026-74872 | 9.3 | 38.2 | — | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool |
| CVE-2026-45721 | 9.0 | 36.6 | — | Algernon: handler.lua discovery walks parent directories above the server root |
| CVE-2026-48565 | 7.8 | 36.2 | — | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-21508 | 7.0 | 36.1 | — | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-16674 | 8.8 | 34.8 | — | IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty |
| CVE-2026-49145 | 7.5 | 25.9 | — | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a pr… |
| CVE-2026-57097 | 6.8 | 25.1 | — | Microsoft XML Security Feature Bypass Vulnerability |
| CVE-2026-11400 | 8.6 | 23.2 | — | Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL |
| CVE-2026-11401 | 8.6 | 23.2 | — | Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL |
| CVE-2026-53819 | 8.7 | 22.4 | — | OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override |
| Vendor | CVEs |
|---|---|
| microsoft | 13 |
| adobe | 5 |
| openclaw | 5 |
| aws | 2 |
| ibm | 2 |
| anysphere | 1 |
| b&r industrial automation | 1 |
| checkmal | 1 |
| cloudnative-pg | 1 |
| eai technologies | 1 |
| jahlives | 1 |
| kovidgoyal | 1 |
| mervinpraison | 1 |
| notepad-plus-plus | 1 |
| open-telemetry | 1 |