Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-610 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 12 | 12 | 0 |
▄██▁
2026-05 2 · 2026-06 5 · 2026-07 5 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47643 | 9.8 | 52.2 | — | Azure Stack Edge Remote Code Execution Vulnerability |
| CVE-2026-34327 | 8.2 | 47.8 | — | Microsoft Partner Center Spoofing Vulnerability |
| CVE-2026-15583 | 8.6 | 40.3 | — | SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header |
| CVE-2026-57301 | 8.8 | 35.9 | — | — |
| CVE-2026-10816 | 7.1 | 34.8 | — | Arbitrary File Read (Unauthenticated) |
| CVE-2026-12788 | 2.1 | 33.4 | — | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml … |
| CVE-2026-55389 | 7.5 | 30.7 | — | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref`… |
| CVE-2026-55390 | 7.5 | 29.3 | — | Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path trav… |
| CVE-2026-45760 | 8.1 | 25.5 | — | Apache Camel K: Camel K Cross-Namespace Build Deputy Attack |
| CVE-2026-0418 | 4.3 | 16.0 | — | Certain NETGEAR devices allow administrators to tamper with system |
| CVE-2026-68562 | 6.2 | 12.7 | — | Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosur… |
| CVE-2026-12879 | 5.9 | 8.8 | — | Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy |
| Vendor | CVEs |
|---|---|
| koxudaxi | 2 |
| microsoft | 2 |
| apache | 1 |
| google cloud | 1 |
| grafana | 1 |
| jenkins project | 1 |
| netgear | 1 |
| netscaler | 1 |
| red hat | 1 |
| zhilink 智互联(深圳)科技有限公司 | 1 |