Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-639 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 670 | 667 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▇
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 53 · 2026-06 164 · 2026-07 242 · 2026-08 207
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55255 | 8.4 | 98.0 | KEV | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attac… |
| CVE-2026-7665 | 5.3 | 93.8 | — | Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Info… |
| CVE-2026-8679 | 7.5 | 73.3 | — | AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference t… |
| CVE-2021-38624 | 6.5 | 72.6 | — | Windows Key Storage Provider Security Feature Bypass Vulnerability |
| CVE-2026-28316 | 9.1 | 67.7 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-8839 | 5.3 | 60.6 | — | MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Referenc… |
| CVE-2026-47101 | 8.7 | 51.8 | — | LiteLLM < 1.83.14 Privilege Escalation via API Key Generation |
| CVE-2026-73298 | 8.7 | 49.5 | — | Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/wr… |
| CVE-2025-34140 | 8.7 | 48.0 | — | ETQ Reliance CG/NXG API Authorization Bypass via ;localized-text URI Suffix |
| CVE-2026-56422 | 9.4 | 46.2 | — | MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields |
| CVE-2026-46453 | 5.3 | 45.0 | — | Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Ca… |
| CVE-2026-28302 | 9.1 | 44.0 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28305 | 9.1 | 43.5 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28308 | 9.1 | 43.5 | — | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-54568 | 4.3 | 42.9 | — | Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to R… |
| CVE-2026-47704 | 7.1 | 42.9 | — | TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage all… |
| CVE-2026-46414 | 8.8 | 42.6 | — | Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking |
| CVE-2026-54105 | 6.9 | 41.0 | — | U.S. GAO EPDS and CBCA EDS user information disclosure |
| CVE-2026-57205 | 4.3 | 40.8 | — | SimpleChat: Authenticated users can access other users' profile metadata through user I… |
| CVE-2026-8890 | 8.8 | 40.2 | — | code100x Mobile API Authentication Bypass via Header Spoofing |
| Vendor | CVEs |
|---|---|
| red hat | 17 |
| apache | 14 |
| mervinpraison | 10 |
| flowiseai | 9 |
| roskus | 9 |
| coollabsio | 8 |
| givanz | 8 |
| microsoft | 8 |
| open-webui | 8 |
| baptistearno | 7 |
| elastic | 7 |
| gitea | 7 |
| ibm | 7 |
| solarwinds | 7 |
| grokability | 6 |