Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-436 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 34 | 34 | 1 |
▃▅█▆
2026-05 3 · 2026-06 8 · 2026-07 13 · 2026-08 10
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-63030 | 9.8 | 99.9 | KEV | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to R… |
| CVE-2026-17084 | 6.0 | 41.4 | — | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 |
| CVE-2026-40165 | 8.7 | 40.9 | — | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi… |
| CVE-2026-6322 | 7.5 | 39.2 | — | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| CVE-2026-18427 | 7.5 | 38.1 | — | @fastify/static vulnerable to route guard bypass via non-canonical path segments |
| CVE-2026-57580 | 9.4 | 36.9 | — | authentik: Account Takeover via SAML NameID Comment Truncation |
| CVE-2026-68968 | 7.5 | 34.9 | — | Apache Airflow: Authorization bypass in the Backfill API through conflicting interpreta… |
| CVE-2026-67201 | 7.7 | 32.4 | — | V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http |
| CVE-2026-47767 | 8.3 | 32.2 | — | Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV… |
| CVE-2026-13676 | 7.5 | 31.7 | — | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| CVE-2026-73615 | 8.7 | 29.6 | — | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch |
| CVE-2026-73614 | 8.7 | 29.0 | — | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation |
| CVE-2026-56669 | 7.5 | 29.0 | — | Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict |
| CVE-2026-44974 | 7.7 | 27.5 | — | Parameter smuggling in @hapi/content header parser allows upload-filter bypass via dupl… |
| CVE-2026-14198 | 9.1 | 22.5 | — | @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter … |
| CVE-2026-45066 | 2.3 | 22.4 | — | Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Diffe… |
| CVE-2026-49332 | 8.5 | 20.8 | — | Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables ident… |
| CVE-2026-47344 | 2.1 | 20.8 | — | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-49473 | 8.8 | 20.1 | — | @cedar-policy/authorization-for-expressjs has an authorization bypass via query string … |
| CVE-2026-16221 | 7.5 | 17.1 | — | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| Vendor | CVEs |
|---|---|
| fast-uri | 4 |
| goauthentik | 2 |
| guzzle | 2 |
| jovancoding | 2 |
| kludex | 2 |
| symfony | 2 |
| @fastify/middie | 1 |
| @fastify/static | 1 |
| apache | 1 |
| benoitc | 1 |
| capgo | 1 |
| cedar-policy | 1 |
| elysiajs | 1 |
| fedify-dev | 1 |
| hapijs | 1 |