Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-798 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 107 | 104 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▇▇
2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 16 · 2026-06 31 · 2026-07 27 · 2026-08 26
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-6693 | 6.5 | 92.3 | KEV | Fortinet FortiOS |
| CVE-2026-44825 | 9.8 | 80.8 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-19900 | 8.2 | 76.6 | — | LB-LINK X-PRO shadow hard-coded credentials |
| CVE-2024-10451 | 5.9 | 58.1 | — | Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process |
| CVE-2025-69425 | 10.0 | 54.0 | — | Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE |
| CVE-2016-20026 | 9.3 | 53.1 | — | ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution |
| CVE-2026-56265 | 9.3 | 52.7 | — | Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key |
| CVE-2026-47281 | 9.6 | 52.4 | — | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-73519 | 9.3 | 46.9 | — | WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret |
| CVE-2026-55579 | 9.8 | 46.2 | — | Pheditor: Hardcoded default password 'admin' with no forced change enables full applica… |
| CVE-2026-13768 | 9.5 | 45.3 | — | Gardyn IoT Hub Use of Hard-coded Credentials |
| CVE-2026-67614 | 9.3 | 43.8 | — | CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal |
| CVE-2026-24444 | 9.3 | 42.9 | — | SDMC NE6037 Hardcoded Password via mgmt.php/npcmd.php |
| CVE-2026-47846 | 9.8 | 39.7 | — | — |
| CVE-2026-11414 | 10.0 | 39.4 | — | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-co… |
| CVE-2026-9139 | 9.3 | 37.8 | — | Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml |
| CVE-2026-19901 | 8.2 | 37.9 | — | LB-LINK X-PRO easycwmp hard-coded credentials |
| CVE-2026-69102 | 9.3 | 37.0 | — | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
| CVE-2025-63823 | 9.8 | 36.6 | — | — |
| CVE-2026-49352 | 9.8 | 36.6 | — | 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass |
| Vendor | CVEs |
|---|---|
| ibm | 6 |
| open ises | 5 |
| acer | 4 |
| jahlives | 3 |
| aqara | 2 |
| autel | 2 |
| bitnami | 2 |
| flowise | 2 |
| lb-link | 2 |
| ruckus networks | 2 |
| tp link systems | 2 |
| tp-link systems | 2 |
| zkteco | 2 |
| agenticmail | 1 |
| altium | 1 |