Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-841 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 17 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▃▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 7 · 2026-07 2 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-43974 | 8.7 | 39.6 | — | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing serve… |
| CVE-2024-0410 | 7.7 | 37.9 | — | Improper Enforcement of Behavioral Workflow in GitLab |
| CVE-2026-19037 | 2.1 | 28.4 | — | WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral work… |
| CVE-2026-42246 | 7.6 | 24.1 | — | net-imap vulnerable to STARTTLS stripping via invalid response timing |
| CVE-2026-48505 | 7.4 | 22.3 | — | Filament: Multi-factor authentication (app) recovery codes can still be used multiple t… |
| CVE-2026-19208 | 2.9 | 19.7 | — | WonderTrader TraderDD.cpp queryTrades behavioral workflow |
| CVE-2026-19993 | 2.1 | 19.4 | — | Webkul Bagisto RMA State Validation update-status behavioral workflow |
| CVE-2026-75081 | 2.1 | 19.4 | — | Webkul Bagisto store behavioral workflow |
| CVE-2026-46540 | 6.5 | 17.8 | — | Nimiq light-blockchain: Light blockchain rebranch issue |
| CVE-2026-13222 | 6.3 | 17.6 | — | Insufficient validation of payment status in pretix-oppwa |
| CVE-2026-13223 | 6.3 | 17.6 | — | Insufficient validation of payment status in pretix-computop |
| CVE-2026-57536 | 6.3 | 17.6 | — | Insufficient validation of payment status in pretix-mollie |
| CVE-2026-8477 | 2.7 | 16.5 | — | — |
| CVE-2026-45023 | 5.4 | 13.0 | — | AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_i… |
| CVE-2026-19213 | 2.1 | 12.3 | — | WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow |
| CVE-2026-18029 | 6.3 | 11.2 | — | Insufficient validation of payment status in pretix-girosolution |
| CVE-2026-16103 | 4.3 | 10.0 | — | Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypas… |
| CVE-2025-36333 | 4.3 | 6.7 | — | Vulnerabilities found in Watson Data Intelligence |
| Vendor | CVEs |
|---|---|
| pretix | 4 |
| webkul | 2 |
| devolutions | 1 |
| filamentphp | 1 |
| gitlab | 1 |
| ibm | 1 |
| nimiq | 1 |
| ninenines | 1 |
| red hat | 1 |
| ruby | 1 |
| significant-gravitas | 1 |