Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-693 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 254 | 238 | 7 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▇▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 3 · 2026-04 3 · 2026-05 13 · 2026-06 90 · 2026-07 82 · 2026-08 44
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21412 | 8.1 | 99.9 | KEV | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2013-0431 | 5.3 | 99.8 | KEV | Oracle Java Runtime Environment (JRE) |
| CVE-2026-32202 | 4.3 | 99.2 | KEV | Windows Shell Spoofing Vulnerability |
| CVE-2026-21510 | 8.8 | 97.8 | KEV | Windows Shell Security Feature Bypass Vulnerability |
| CVE-2026-21513 | 8.8 | 96.5 | KEV | MSHTML Framework Security Feature Bypass Vulnerability |
| CVE-2024-38217 | 5.4 | 95.2 | KEV | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-38226 | 7.3 | 84.5 | KEV | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2023-38157 | 6.5 | 83.2 | — | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2025-27472 | 5.4 | 73.2 | — | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-30052 | 4.7 | 69.4 | — | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-27893 | 8.8 | 69.2 | — | vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user securit… |
| CVE-2024-43487 | 6.5 | 66.5 | — | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-20673 | 7.8 | 65.4 | — | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-41316 | 8.1 | 63.9 | — | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class |
| CVE-2024-11734 | 6.5 | 58.5 | — | Org.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security… |
| CVE-2026-50646 | 7.8 | 58.4 | — | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-32225 | 8.8 | 57.1 | — | Windows Shell Security Feature Bypass Vulnerability |
| CVE-2026-34348 | 6.5 | 57.1 | — | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-20824 | 5.5 | 56.9 | — | Windows Remote Assistance Security Feature Bypass Vulnerability |
| CVE-2026-47140 | 10.0 | 54.3 | — | vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code… |
| Vendor | CVEs |
|---|---|
| 75 | |
| microsoft | 34 |
| mozilla | 21 |
| apple | 10 |
| twigphp | 9 |
| patriksimek | 5 |
| cure53 | 3 |
| jahlives | 3 |
| jenkins project | 3 |
| mervinpraison | 3 |
| picklescan | 3 |
| electron | 2 |
| fission | 2 |
| indian motorcycle | 2 |
| kerberosmansour | 2 |