Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-489 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 12 | 0 |
▂▁▁▁▁▁▁▃▂█▃
2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 7 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-66405 | 8.7 | 41.2 | — | — |
| CVE-2026-66403 | 8.7 | 36.2 | — | — |
| CVE-2026-59092 | 7.0 | 31.0 | — | JuiceFS - Authentication Bypass via pprof and metrics Endpoints |
| CVE-2026-9133 | 8.3 | 27.6 | — | Arbitrary file read in rabbitmq-aws plugin |
| CVE-2026-41186 | 6.0 | 27.5 | — | Unauthenticated Go pprof exposure in Calico debug server |
| CVE-2026-49188 | 8.7 | 24.6 | — | Elevated Root Command Execution via ai_cmd Sockets |
| CVE-2025-4106 | 8.9 | 24.0 | — | WatchGuard Firebox leftover debug code vulnerability |
| CVE-2026-45728 | 7.5 | 22.9 | — | Algernon: Single-file mode unconditionally enables debug mode |
| CVE-2026-58191 | 6.1 | 16.9 | — | Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes |
| CVE-2026-58378 | 8.6 | 15.6 | — | Allwinner TV Box TV98 ADB exposed on network |
| CVE-2026-54798 | 7.1 | 15.3 | — | — |
| CVE-2026-65893 | 7.0 | 5.5 | — | Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-54799 | 8.4 | 2.8 | — | — |