Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-494 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 16 | 0 |
▅▇▃█
2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-9089 | 8.8 | 23.9 | — | — |
| CVE-2026-48046 | 9.3 | 19.8 | — | Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC H… |
| CVE-2026-55698 | 8.8 | 18.5 | — | pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc… |
| CVE-2026-9037 | 9.3 | 16.1 | — | Download of code without integrity check in XCharge C6 |
| CVE-2026-66398 | 9.4 | 15.5 | — | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
| CVE-2026-45058 | 9.4 | 14.5 | — | electerm: Import unsafe bookmark data could lead to unsafe operation when click local t… |
| CVE-2026-55697 | 8.8 | 7.2 | — | pnpm: Repository-controlled configDependencies can select a pacquet native install engine |
| CVE-2026-53970 | 7.5 | 6.8 | — | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb |
| CVE-2026-49241 | 8.7 | 5.1 | — | Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS … |
| CVE-2026-50562 | 9.3 | 4.8 | — | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows |
| CVE-2021-47986 | 7.7 | 2.2 | — | Parse Server - Unreviewed Code Execution via Malicious Version Tags |
| CVE-2021-47987 | 7.7 | 2.2 | — | Parse Server - Arbitrary Code Execution via Malicious Version Tags |
| CVE-2026-13433 | 9.6 | 1.7 | — | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-12259 | 5.3 | 1.0 | — | Improper Input Validation in nltk/nltk |
| CVE-2026-0392 | 7.3 | 0.0 | — | eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update |
| CVE-2026-76241 | 7.3 | — | — | stigmem Plugin Signature Enforcement Bypass via Configuration |
| Vendor | CVEs |
|---|---|
| parse-community | 2 |
| pnpm | 2 |
| angular | 1 |
| connectwise | 1 |
| eidetic-labs | 1 |
| electerm | 1 |
| ibm | 1 |
| labring | 1 |
| latvijas valsts radio un televīzijas centrs (lvrtc) | 1 |
| lucasgelfond | 1 |
| nltk | 1 |
| thorsten | 1 |
| truelockmc | 1 |
| xcharge | 1 |