Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-625 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 6 | 6 | 0 |
▃▆▁█
2026-05 1 · 2026-06 2 · 2026-07 0 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-64940 | 8.8 | 33.2 | — | — |
| CVE-2026-40110 | 7.6 | 27.2 | — | jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat |
| CVE-2026-73845 | 5.3 | 13.3 | — | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) |
| CVE-2026-44587 | 6.1 | 13.2 | — | CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters |
| CVE-2026-19278 | 6.8 | 11.6 | — | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m… |
| CVE-2026-37737 | 6.5 | 6.2 | — | — |
| Vendor | CVEs |
|---|---|
| carrierwaveuploader | 1 |
| jupyter-server | 1 |
| nishishi factory | 1 |
| ondata | 1 |
| red hat | 1 |