Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-647 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
▃▁█▃
2026-05 1 · 2026-06 0 · 2026-07 3 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-5222 | 2.3 | 39.4 | — | Cargo can be coerced to share credentials between registries |
| CVE-2026-62685 | 8.1 | 25.2 | — | File Browser: Colliding username normalization gives two users the same home directory |
| CVE-2026-59731 | 8.2 | 19.0 | — | Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicali… |
| CVE-2026-8384 | 5.3 | 13.9 | — | — |
| CVE-2026-15970 | 4.2 | 5.6 | — | L7 intention authorization bypass via custom public listener |
| Vendor | CVEs |
|---|---|
| eclipse foundation | 1 |
| filebrowser | 1 |
| hashicorp | 1 |
| rust | 1 |
| withastro | 1 |