Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-532 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 90 | 84 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▅▇██
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 1 · 2026-01 1 · 2026-02 1 · 2026-03 2 · 2026-04 4 · 2026-05 14 · 2026-06 19 · 2026-07 22 · 2026-08 21
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-25002 | 6.8 | 61.0 | — | Azure Local Cluster Information Disclosure Vulnerability |
| CVE-2026-54236 | 5.3 | 54.5 | — | vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router |
| CVE-2026-20818 | 6.2 | 51.0 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-65945 | 6.5 | 46.5 | — | Apache Ranger: Logs contain replayable JWT bearer tokens |
| CVE-2026-12053 | 7.5 | 45.3 | — | Insertion of Sensitive Information into Log File in GitLab |
| CVE-2026-21222 | 5.5 | 44.7 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-31245 | 7.5 | 42.0 | — | WordPress ConvertKit plugin <= 2.4.5 - Email Disclosure in Log File vulnerability |
| CVE-2026-49200 | 10.0 | 41.9 | — | Acer Wave 7 router: Broken Access Control |
| CVE-2024-9621 | 5.3 | 41.9 | — | Io.quarkiverse.cxf:quarkus-cxf: quarkus cxf may log user password and secret to applica… |
| CVE-2024-31249 | 7.5 | 41.3 | — | WordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vul… |
| CVE-2026-41184 | 6.0 | 41.0 | — | ServiceAccount token disclosure via install-cni container logs |
| CVE-2026-64800 | 5.7 | 40.2 | — | — |
| CVE-2026-20239 | 6.5 | 39.8 | — | Sensitive Information Disclosure through Log Files in Splunk Enterprise |
| CVE-2026-32218 | 5.5 | 36.5 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-32215 | 5.5 | 35.3 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-32217 | 5.5 | 35.2 | — | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-12947 | 7.5 | 32.8 | — | IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Con… |
| CVE-2026-19363 | 5.5 | 32.4 | — | lmammino oidc-authorizer Lambda Authorizer handler.rs log file |
| CVE-2026-65589 | 5.1 | 30.4 | — | n8n before 1.123.64 Credential Exposure via LLM Node Execution Data |
| CVE-2020-36876 | 8.7 | 29.8 | — | ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020 |
| Vendor | CVEs |
|---|---|
| ibm | 9 |
| microsoft | 7 |
| red hat | 7 |
| dell | 4 |
| hclsoftware | 4 |
| mongodb | 4 |
| apple | 3 |
| tigera | 3 |
| acer | 2 |
| apache | 2 |
| gitlab | 2 |
| jetbrains | 2 |
| open-telemetry | 2 |
| renovatebot | 2 |
| admidio | 1 |