Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-829 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 82 | 79 | 1 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃██▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 7 · 2026-06 26 · 2026-07 26 · 2026-08 19
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-0770 | 9.8 | 99.0 | KEV | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote C… |
| CVE-2026-59865 | 9.3 | 87.1 | — | Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot… |
| CVE-2026-59867 | 7.1 | 78.3 | — | Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref |
| CVE-2026-73851 | 6.1 | 71.8 | — | Kiota: Path traversal in generated plugin manifest static_template.file reference (perc… |
| CVE-2026-71471 | 9.0 | 71.3 | — | Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagat… |
| CVE-2026-59864 | 9.3 | 67.6 | — | Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions |
| CVE-2026-44359 | 10.0 | 60.2 | — | Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target F… |
| CVE-2026-43999 | 9.9 | 59.3 | — | vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb… |
| CVE-2026-43003 | 7.5 | 54.5 | — | — |
| CVE-2026-57102 | 8.8 | 52.7 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-62902 | 6.5 | 52.5 | — | .NET Information Disclosure Vulnerability |
| CVE-2024-30092 | 8.0 | 49.2 | — | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-58116 | 9.3 | 48.1 | — | LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path |
| CVE-2026-5241 | 9.6 | 43.5 | — | Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers |
| CVE-2026-46529 | 8.4 | 42.5 | — | PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen |
| CVE-2026-67623 | 8.6 | 42.5 | — | Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook |
| CVE-2026-18408 | 8.8 | 42.4 | — | PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary c… |
| CVE-2026-44688 | 8.4 | 41.2 | — | — |
| CVE-2026-46580 | 8.4 | 41.2 | — | — |
| CVE-2026-6464 | 8.1 | 40.3 | — | PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands |
| Vendor | CVEs |
|---|---|
| microsoft | 9 |
| jetbrains | 8 |
| eclipse foundation | 5 |
| pnpm | 3 |
| vim | 3 |
| concrete cms | 2 |
| docker | 2 |
| duck-organization | 2 |
| mervinpraison | 2 |
| openclaw | 2 |
| red hat | 2 |
| synology | 2 |
| axllent | 1 |
| cdeust | 1 |
| cherryhq | 1 |