Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-732 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 93 | 90 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▅█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 11 · 2026-06 21 · 2026-07 39 · 2026-08 14
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-13374 | 4.3 | 98.4 | KEV | Fortinet FortiOS and FortiADC |
| CVE-2026-32315 | 5.5 | 65.7 | — | motionEye: World-Readable Configuration File Exposes Admin Password Hash |
| CVE-2021-26434 | 7.8 | 56.4 | — | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2026-10591 | 8.6 | 48.9 | — | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths |
| CVE-2026-73664 | 8.6 | 48.5 | — | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module |
| CVE-2026-53486 | 9.1 | 48.0 | — | decompress: Archive extraction can create files and links outside the target directory |
| CVE-2024-45497 | 7.6 | 44.9 | — | Openshift-api: openshift-controller-manager/build: build process in openshift allows ov… |
| CVE-2026-61155 | 9.1 | 39.1 | — | — |
| CVE-2026-43721 | 6.5 | 36.6 | — | — |
| CVE-2026-49340 | 8.1 | 35.8 | — | gonic has arbitrary file write in createPlaylist: any authenticated user can write play… |
| CVE-2026-42497 | 7.5 | 35.0 | — | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled pat… |
| CVE-2026-44878 | 7.2 | 34.6 | — | Authenticated Path Traversal allows Unauthorized Access in Web Interface |
| CVE-2025-41118 | 9.1 | 34.1 | — | Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing typ… |
| CVE-2026-4757 | 7.2 | 32.3 | — | — |
| CVE-2026-61186 | 9.4 | 31.9 | — | — |
| CVE-2025-69426 | 10.0 | 30.1 | — | Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE |
| CVE-2026-9508 | 10.0 | 27.2 | — | Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar |
| CVE-2026-24049 | 7.1 | 23.9 | — | wheel Allows Arbitrary File Permission Modification via Path Traversal |
| CVE-2026-63522 | 7.8 | 20.3 | — | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-61892 | 8.7 | 19.9 | — | Weintek cMT3092X Incorrect Permission Assignment for Critical Resource |