Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-441 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 38 | 37 | 0 |
▁▁▁▁▂▁▅█▆
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 1 · 2026-06 8 · 2026-07 15 · 2026-08 10
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-62718 | 6.3 | 64.7 | — | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| CVE-2026-44494 | 8.7 | 61.3 | — | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-23751 | 9.3 | 56.4 | — | Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting |
| CVE-2026-42043 | 7.2 | 48.9 | — | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo… |
| CVE-2026-63643 | 6.3 | 39.2 | — | MagicMirror: ssrf calendar .js |
| CVE-2026-49086 | 6.5 | 35.7 | — | Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and to… |
| CVE-2026-46592 | 7.5 | 32.9 | — | Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed n… |
| CVE-2026-17107 | 8.5 | 27.8 | — | Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cl… |
| CVE-2026-56675 | 8.3 | 24.3 | — | 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs |
| CVE-2026-73079 | 8.5 | 23.7 | — | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant re… |
| CVE-2026-16456 | 6.5 | 23.7 | — | Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account… |
| CVE-2026-44945 | 9.1 | 23.0 | — | Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
| CVE-2026-72526 | 9.9 | 22.5 | — | Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub ten… |
| CVE-2026-53931 | 6.9 | 22.2 | — | NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint |
| CVE-2026-42933 | 10.0 | 21.1 | — | Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs |
| CVE-2026-72640 | 6.5 | 16.4 | — | Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namesp… |
| CVE-2026-43910 | 8.2 | 15.3 | — | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in Appiu… |
| CVE-2026-16158 | 10.0 | 14.2 | — | @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key coll… |
| CVE-2026-49821 | 7.7 | 14.2 | — | Fission: Cross-namespace Environment reference in Package allows build-time command exe… |
| CVE-2026-70398 | 9.6 | 13.5 | — | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonam… |
| Vendor | CVEs |
|---|---|
| red hat | 6 |
| axios | 3 |
| apache | 2 |
| better-auth | 2 |
| 2 | |
| @better-auth | 1 |
| @fastify/reply-from | 1 |
| acacode | 1 |
| angular | 1 |
| appium | 1 |
| coder | 1 |
| datadog | 1 |
| decolua | 1 |
| elastic | 1 |
| fission | 1 |