Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-551 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 8 | 8 | 0 |
▃▃██▁▁
2026-03 1 · 2026-04 1 · 2026-05 3 · 2026-06 3 · 2026-07 0 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44575 | 7.5 | 73.7 | — | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes |
| CVE-2026-44574 | 8.1 | 47.8 | — | Next.js: Middleware / Proxy bypass through dynamic route parameter injection |
| CVE-2026-44573 | 7.5 | 47.0 | — | Next.js: Middleware / Proxy bypass in Pages Router applications using i18n |
| CVE-2016-20030 | 9.3 | 44.3 | — | ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction |
| CVE-2026-28808 | 8.3 | 43.2 | — | ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path … |
| CVE-2026-50559 | 7.5 | 38.4 | — | Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities |
| CVE-2026-45832 | 8.8 | 20.9 | — | — |
| CVE-2026-57920 | 7.7 | 17.8 | — | — |