Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-497 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 63 | 62 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 19 · 2026-07 27 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-25358 | 8.7 | 45.4 | — | D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi |
| CVE-2025-46421 | 6.8 | 43.6 | — | Libsoup: information disclosure may leads libsoup client sends authorization header to … |
| CVE-2026-14808 | 9.3 | 39.0 | — | PROG MIS|Prog Management System - Exposure of Sensitive Information |
| CVE-2026-41928 | 6.9 | 35.1 | — | Vvveb < 1.0.8.2 Information Disclosure via Cron Controller |
| CVE-2026-59528 | 7.5 | 33.2 | — | WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure… |
| CVE-2026-55726 | 6.9 | 32.7 | — | Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere |
| CVE-2026-49068 | 7.5 | 32.0 | — | WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-50294 | 6.2 | 30.7 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-56124 | 8.7 | 29.8 | — | phpUploader < 2.0.2 Unauthenticated Database Exposure via index model |
| CVE-2026-49056 | 7.5 | 29.8 | — | WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels p… |
| CVE-2026-66444 | 6.5 | 28.8 | — | WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerab… |
| CVE-2026-40796 | 6.5 | 27.7 | — | WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability |
| CVE-2026-42660 | 6.5 | 27.7 | — | WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability |
| CVE-2026-48878 | 6.5 | 27.7 | — | WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-57316 | 6.5 | 27.7 | — | WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-54824 | 7.5 | 23.1 | — | WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability |
| CVE-2026-44945 | 9.1 | 23.0 | — | Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
| CVE-2026-32468 | 7.5 | 22.9 | — | WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability |
| CVE-2026-34891 | 7.5 | 22.9 | — | WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive Data Exposu… |
| CVE-2026-59548 | 7.5 | 22.9 | — | WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vu… |
| Vendor | CVEs |
|---|---|
| crocoblock | 3 |
| sap_se | 3 |
| pronetiqs | 2 |
| ads wpquads | 1 |
| amd | 1 |
| bdthemes | 1 |
| bookingwp | 1 |
| bootstrapped ventures | 1 |
| byteflows | 1 |
| chouby | 1 |
| chrisvrichardson | 1 |
| complianz | 1 |
| conekta group | 1 |
| d-link | 1 |
| dell | 1 |