Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-636 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 18 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▆█▇
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 4 · 2026-07 6 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43532 | 8.8 | 95.8 | — | Remote Registry Service Elevation of Privilege Vulnerability |
| CVE-2026-53913 | 9.8 | 52.0 | — | Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins… |
| CVE-2026-73421 | 9.1 | 48.1 | — | NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (a… |
| CVE-2026-50528 | 8.2 | 43.7 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-70452 | 9.1 | 38.4 | — | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
| CVE-2026-68746 | 7.7 | 37.4 | — | Livebook Teams identity check fails open when the deployment group is unresolvable, all… |
| CVE-2026-54762 | 5.9 | 34.1 | — | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails |
| CVE-2026-69306 | 8.2 | 33.8 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-46482 | 5.3 | 25.8 | — | MyBB: Security Question insufficient validation |
| CVE-2026-42246 | 7.6 | 24.1 | — | net-imap vulnerable to STARTTLS stripping via invalid response timing |
| CVE-2026-44094 | 8.3 | 17.7 | — | Fallback to second RAUC slot with default credentials |
| CVE-2026-53852 | 2.3 | 11.0 | — | OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing |
| CVE-2026-54291 | 8.2 | 10.6 | — | Silent channel-binding authentication downgrade via unsupported certificate algorithms |
| CVE-2026-53837 | 6.3 | 8.8 | — | OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers |
| CVE-2026-62235 | 2.3 | 6.7 | — | Grav Flex-Objects < 1.4.3 Authorization Bypass via API |
| CVE-2026-53712 | 8.2 | 6.4 | — | SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algo… |
| CVE-2026-49317 | 1.0 | 4.1 | — | Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent … |
| CVE-2026-49318 | 1.0 | 4.1 | — | Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent … |
| CVE-2026-55568 | 5.9 | 1.3 | — | Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| indian motorcycle | 2 |
| openclaw | 2 |
| apache | 1 |
| getgrav | 1 |
| guzzle | 1 |
| livebook-dev | 1 |
| mybb | 1 |
| nextauthjs | 1 |
| ongres | 1 |
| pgjdbc | 1 |
| phoenix contact | 1 |
| rsyncproject | 1 |
| ruby | 1 |
| traefik | 1 |