Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-501 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 4 | 1 |
▃▁▁▁▁▁▁▁▃█▁
2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 3 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2026-49458 | 6.1 | 31.7 | — | DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-… |
| CVE-2026-44091 | 8.8 | 25.7 | — | Creation of a new configuration by posting a malicious ID to MQTT |
| CVE-2026-33828 | 7.8 | 23.7 | — | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability |
| CVE-2026-65902 | 5.3 | 11.5 | — | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags |
| Vendor | CVEs |
|---|---|
| cure53 | 2 |
| microsoft | 1 |
| oracle | 1 |
| phoenix contact | 1 |