Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-73 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 160 | 150 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▇█▇
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 4 · 2026-02 2 · 2026-03 0 · 2026-04 1 · 2026-05 12 · 2026-06 41 · 2026-07 47 · 2026-08 43
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-20872 | 6.5 | 97.2 | — | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2026-20925 | 6.5 | 96.9 | — | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2026-21249 | 3.3 | 95.5 | — | Windows NTLM Spoofing Vulnerability |
| CVE-2025-71334 | 9.3 | 89.4 | — | Flowise - Arbitrary File Access via Missing Chat Flow ID Validation |
| CVE-2025-68428 | 9.2 | 80.2 | — | jsPDF has Local File Inclusion/Path Traversal vulnerability |
| CVE-2023-35384 | 6.5 | 73.2 | — | Windows HTML Platforms Security Feature Bypass Vulnerability |
| CVE-2026-8450 | 9.1 | 70.3 | — | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() |
| CVE-2025-71324 | 8.7 | 69.9 | — | Flowise - Arbitrary File Read via chatId Parameter |
| CVE-2026-11526 | 9.8 | 69.3 | — | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-… |
| CVE-2024-43581 | 7.1 | 68.9 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2025-4603 | 9.1 | 68.7 | — | eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion |
| CVE-2024-38029 | 7.5 | 68.7 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2024-43615 | 7.1 | 65.1 | — | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
| CVE-2026-11527 | 8.6 | 62.2 | — | Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file … |
| CVE-2023-21800 | 7.8 | 61.8 | — | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2025-29819 | 6.2 | 59.0 | — | Windows Admin Center in Azure Portal Information Disclosure Vulnerability |
| CVE-2026-65802 | 7.4 | 57.5 | — | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2025-71338 | 10.0 | 55.8 | — | Flowise - Arbitrary File Write to Remote Code Execution via document-store API |
| CVE-2025-71333 | 9.3 | 53.8 | — | Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint |
| CVE-2026-17184 | 9.8 | 53.6 | — | IBM Db2 Mirror for i is affected by multiple vulnerabilities |
| Vendor | CVEs |
|---|---|
| microsoft | 24 |
| ibm | 5 |
| mbs | 5 |
| progress | 5 |
| flowise | 4 |
| pnpm | 4 |
| sourcecodester | 4 |
| getgrav | 3 |
| apache | 2 |
| asus | 2 |
| cisco | 2 |
| docling-project | 2 |
| eclipse foundation | 2 |
| emagicone | 2 |
| gitpython-developers | 2 |