Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-749 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 25 | 3 |
▃▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▅█▆▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 9 · 2026-07 6 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2010-0738 | 5.3 | 99.6 | KEV | Red Hat JBoss |
| CVE-2010-1428 | 7.5 | 99.1 | KEV | Red Hat JBoss |
| CVE-2018-19322 | 7.8 | 77.7 | KEV | GIGABYTE Multiple Products |
| CVE-2025-26651 | 6.5 | 82.1 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability |
| CVE-2026-54753 | 5.9 | 54.2 | — | Nx: `nx graph` dev server permissive CORS policy |
| CVE-2026-41283 | 9.9 | 51.5 | — | — |
| CVE-2026-53633 | 9.8 | 45.0 | — | Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE |
| CVE-2026-14620 | 4.7 | 42.2 | — | webpack-dev-server vulnerable to cross-site request forgery via internal developer endp… |
| CVE-2026-68823 | 9.1 | 40.8 | — | Azure Confidential Ledger Remote Code Execution Vulnerability |
| CVE-2025-14713 | 7.5 | 39.2 | — | — |
| CVE-2026-45489 | 6.5 | 39.2 | — | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-18901 | 7.3 | 37.8 | — | H3C NX15 Web API esps service.add routine |
| CVE-2026-55454 | 9.9 | 32.5 | — | Appsmith: Caddy admin API exposed without authentication |
| CVE-2026-48056 | 10.0 | 31.2 | — | Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
| CVE-2026-4051 | 7.2 | 30.1 | — | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Aut… |
| CVE-2025-53827 | 9.1 | 29.4 | — | ownCloud Core: Updater has an exposed dangerous method or function |
| CVE-2026-44836 | 6.5 | 27.5 | — | view_component: Preview Route Can Dispatch Inherited Helper Methods |
| CVE-2026-12060 | 6.9 | 24.1 | — | Hepta Platforms|Heptabase - Exposed Dangerous |
| CVE-2026-44107 | 8.7 | 23.7 | — | Exposed Reboot via Modbus |
| CVE-2026-52877 | 8.3 | 23.2 | — | Streambert : Insecure Protocol Execution in open-external IPC Handler |
| Vendor | CVEs |
|---|---|
| microsoft | 3 |
| nuxt | 2 |
| truelockmc | 2 |
| appsmithorg | 1 |
| gitroomhq | 1 |
| h3c | 1 |
| hepta platforms | 1 |
| home assistant | 1 |
| home-assistant | 1 |
| ibm | 1 |
| lenovo | 1 |
| logseq | 1 |
| mediatek | 1 |
| nautobot | 1 |
| nrwl | 1 |