Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-668 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 35 | 27 | 0 |
▂▂▁▁▂▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▁▂▁▄▇█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 8 · 2026-07 10 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21626 | 8.6 | 97.0 | — | runc container breakout through process.cwd trickery and leaked fds |
| CVE-2026-44008 | 9.8 | 55.4 | — | vm2: Snabox breakout via `neutralizeArraySpeciesBatch` |
| CVE-2026-44009 | 9.8 | 54.1 | — | vm2: Sandbox Breakout Through Null Proto Exception |
| CVE-2026-45411 | 9.8 | 44.6 | — | vm2: Sandbox Breakout Using Async Generator |
| CVE-2026-42535 | 9.1 | 43.0 | — | Apache HTTP Server: mod_dav_fs protected directory access |
| CVE-2026-14960 | 9.8 | 39.4 | — | CVE-2026-14960 |
| CVE-2026-59835 | 8.6 | 38.2 | — | — |
| CVE-2026-45077 | 8.3 | 37.4 | — | Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener |
| CVE-2026-56077 | 7.1 | 37.2 | — | PraisonAI - Information Disclosure via Shared MultiAgentLedger State |
| CVE-2026-72764 | 5.8 | 30.7 | — | n8n before 1.123.67 Module Cache Poisoning via Code Node |
| CVE-2024-36032 | 7.1 | 28.3 | — | Bluetooth: qca: fix info leak when fetching fw build id |
| CVE-2026-67427 | 8.6 | 27.0 | — | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denyli… |
| CVE-2026-57231 | 7.5 | 24.0 | — | Podman: Malformed Image can trick podman run into leaking host environment variables in… |
| CVE-2026-47141 | 6.9 | 23.5 | — | vm2: NodeVM observability builtins leak host process and HTTP request data |
| CVE-2024-43881 | 7.1 | 23.3 | — | wifi: ath12k: change DMA direction while mapping reinjected packets |
| CVE-2026-73843 | 9.6 | 21.7 | — | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gate… |
| CVE-2026-50202 | 5.9 | 21.5 | — | Steeltoe's static JWKS cache shared across schemes and never invalidated |
| CVE-2026-53648 | 5.1 | 18.4 | — | FOSSBilling: Downloadable product files can be overwritten through filename collisions |
| CVE-2026-14611 | 5.3 | 17.0 | — | DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of r… |
| CVE-2021-47401 | 5.5 | 16.7 | — | ipack: ipoctal: fix stack information leak |
| Vendor | CVEs |
|---|---|
| linux | 6 |
| patriksimek | 4 |
| activepieces | 1 |
| apache | 1 |
| craftcms | 1 |
| deepmyst | 1 |
| dräger | 1 |
| electron | 1 |
| flytohub | 1 |
| fortinet | 1 |
| fossbilling | 1 |
| lima-vm | 1 |
| n8n-io | 1 |
| openchoreo | 1 |
| openclaw | 1 |