Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-697 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 18 | 0 |
▃▅█▄
2026-05 2 · 2026-06 5 · 2026-07 8 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44249 | 8.1 | 60.9 | — | Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking |
| CVE-2026-75110 | 9.3 | 41.7 | — | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET |
| CVE-2026-49340 | 8.1 | 35.8 | — | gonic has arbitrary file write in createPlaylist: any authenticated user can write play… |
| CVE-2026-59890 | 6.1 | 33.9 | — | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (… |
| CVE-2026-55771 | 8.8 | 27.7 | — | CedarJava has policy injection, type confusion, and incorrect equality comparison vulne… |
| CVE-2026-14687 | 5.5 | 26.2 | — | 666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_result… |
| CVE-2026-22660 | 8.6 | 25.8 | — | FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint |
| CVE-2026-45569 | 8.1 | 24.4 | — | Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug) |
| CVE-2026-48032 | 8.3 | 23.7 | — | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers |
| CVE-2026-67207 | 8.7 | 22.6 | — | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController |
| CVE-2026-45567 | 8.3 | 15.8 | — | Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt |
| CVE-2026-14617 | 1.3 | 15.0 | — | NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStre… |
| CVE-2026-50029 | 5.3 | 14.4 | — | js-toml has silent type confusion via falsy-primitive duplicate-key bypass |
| CVE-2026-9369 | 1.9 | 13.9 | — | NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins c… |
| CVE-2026-20765 | 4.6 | 13.8 | — | — |
| CVE-2026-65903 | 5.1 | 10.2 | — | DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS |
| CVE-2026-47202 | 9.3 | 6.9 | — | Kavita: Pre-Auth Account Takeover |
| CVE-2026-10097 | 8.3 | 5.8 | — | ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and stati… |
| Vendor | CVEs |
|---|---|
| nousresearch | 2 |
| roxy-wi | 2 |
| 666ghj | 1 |
| cedar-policy | 1 |
| cure53 | 1 |
| flaskbb | 1 |
| kareadita | 1 |
| kerberosmansour | 1 |
| memtensor | 1 |
| netty | 1 |
| pypa | 1 |
| sentriz | 1 |
| sunnyadn | 1 |
| wolfcms | 1 |
| wolfssl | 1 |