Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-522 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 95 | 93 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 36 · 2026-08 24
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-30116 | 9.8 | 99.7 | KEV | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6 |
| CVE-2025-26628 | 7.3 | 67.0 | — | Azure Local Cluster Information Disclosure Vulnerability |
| CVE-2026-32315 | 5.5 | 65.7 | — | motionEye: World-Readable Configuration File Exposes Admin Password Hash |
| CVE-2026-57219 | 8.7 | 53.2 | — | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoi… |
| CVE-2026-62839 | 6.5 | 47.3 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47282 | 6.5 | 46.6 | — | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-62882 | 4.3 | 46.1 | — | Microsoft Outlook Spoofing Vulnerability |
| CVE-2026-9079 | 9.8 | 45.3 | — | stale proxy password leak |
| CVE-2026-7312 | 7.5 | 36.9 | — | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
| CVE-2026-32171 | 8.8 | 36.8 | — | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-62684 | 2.7 | 32.6 | — | File Browser: Share API exposes the password hash and bypass token |
| CVE-2026-48295 | 7.5 | 32.2 | — | CAI Content Credentials | Insufficiently Protected Credentials (CWE-522) |
| CVE-2026-8926 | 9.1 | 30.9 | — | password leak with netrc and user in URL |
| CVE-2026-50017 | 6.9 | 30.9 | — | pnpm binds unscoped user-level npm auth credentials to a repository-selected registry |
| CVE-2026-62327 | 9.3 | 30.3 | — | 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats |
| CVE-2026-56843 | 9.9 | 29.6 | — | — |
| CVE-2026-15806 | 6.0 | 29.6 | — | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme… |
| CVE-2026-44938 | 8.8 | 29.0 | — | Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent |
| CVE-2026-53632 | 5.5 | 28.1 | — | NTLMv2 hash disclosure via UNC path handling on Windows |
| CVE-2026-53454 | 6.9 | 27.5 | — | Blueprint Studio stored Git credentials in plaintext Git credential store |
| Vendor | CVEs |
|---|---|
| microsoft | 5 |
| openclaw | 5 |
| flytohub | 3 |
| siyuan-note | 3 |
| aehrc | 2 |
| curl | 2 |
| gitlab | 2 |
| ha-china | 2 |
| hapijs | 2 |
| palo alto networks | 2 |
| pnpm | 2 |
| progress | 2 |
| red hat | 2 |
| schneider electric | 2 |
| acacode | 1 |