Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-807 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 22 | 3 |
▃▂▁▂▃▄▃█
2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 9
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34486 | 7.5 | 99.6 | KEV | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |
| CVE-2026-21509 | 7.8 | 99.4 | KEV | Microsoft Office Security Feature Bypass Vulnerability |
| CVE-2026-21514 | 7.8 | 72.5 | KEV | Microsoft Word Security Feature Bypass Vulnerability |
| CVE-2026-20849 | 7.5 | 60.4 | — | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-64827 | 9.3 | 36.4 | — | Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
| CVE-2026-54730 | 8.6 | 30.7 | — | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorE… |
| CVE-2026-0390 | 6.7 | 24.6 | — | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-53789 | 7.1 | 23.8 | — | rsync < 3.5.0 Arbitrary File Deletion via Malicious File List |
| CVE-2026-9077 | 8.5 | 23.7 | — | Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Pr… |
| CVE-2026-43935 | 8.1 | 22.3 | — | e107: Host Header Injection in e107 password reset enables phishing |
| CVE-2026-48491 | 7.8 | 20.5 | — | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS by… |
| CVE-2026-13059 | 8.6 | 19.6 | — | Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Co… |
| CVE-2026-18705 | 7.1 | 19.3 | — | Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Pro… |
| CVE-2026-19579 | 5.3 | 15.1 | — | Snipe-IT Checkout Request Cancellation IDOR |
| CVE-2026-58239 | 3.7 | 12.8 | — | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-44649 | 9.8 | 12.5 | — | SillyTavern: Authentication Bypass via SSO Header Injection |
| CVE-2026-9561 | 8.8 | 9.3 | — | — |
| CVE-2026-64934 | 5.3 | 8.2 | — | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision |
| CVE-2026-16093 | 5.4 | 7.8 | — | Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypas… |
| CVE-2026-48980 | 6.3 | 7.4 | — | pam_usb: getenv() used in PAM context allows environment variable injection into local-… |
| Vendor | CVEs |
|---|---|
| microsoft | 4 |
| mongodb | 2 |
| apache | 1 |
| e107inc | 1 |
| eclipse foundation | 1 |
| goauthentik | 1 |
| grokability | 1 |
| ibm | 1 |
| mcdope | 1 |
| openclaw | 1 |
| quanovate tech inc. (operating as mira / mira care) | 1 |
| red hat | 1 |
| rsyncproject | 1 |
| sap_se | 1 |
| sillytavern | 1 |