Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-862 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1370 | 1359 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▇
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 4 · 2026-05 134 · 2026-06 368 · 2026-07 454 · 2026-08 397
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-20362 | 8.6 | 99.7 | KEV | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense |
| CVE-2024-57726 | 9.9 | 99.2 | KEV | SimpleHelp SimpleHelp |
| CVE-2026-27771 | 8.2 | 98.6 | — | Gitea Composer package source links use insufficient permission checks |
| CVE-2023-5612 | 5.3 | 91.3 | — | Missing Authorization in GitLab |
| CVE-2026-73296 | 9.4 | 84.2 | — | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control a… |
| CVE-2026-10768 | 9.8 | 67.3 | — | LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039 |
| CVE-2024-38190 | 8.6 | 61.7 | — | Power Platform Information Disclosure Vulnerability |
| CVE-2026-44595 | 4.3 | 59.6 | — | Yamcs: Unauthorized user enumeration via IAM API endpoints |
| CVE-2026-48168 | 10.0 | 57.1 | — | PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name |
| CVE-2026-54475 | 7.5 | 57.0 | — | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination own… |
| CVE-2026-57206 | 8.6 | 56.6 | — | SimpleChat plugin validation endpoints missing authentication and authorization |
| CVE-2025-24249 | 9.8 | 54.6 | — | — |
| CVE-2026-66326 | 8.8 | 52.8 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-40375 | 6.5 | 52.7 | — | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2026-47281 | 9.6 | 52.4 | — | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2025-21416 | 8.5 | 52.1 | — | Azure Virtual Desktop Elevation of Privilege Vulnerability |
| CVE-2026-59113 | 8.8 | 50.1 | — | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-48582 | 9.6 | 50.0 | — | Microsoft Exchange Online Elevation of Privilege Vulnerability |
| CVE-2026-58275 | 9.8 | 49.7 | — | Azure DNS Elevation of Privilege Vulnerability |
| CVE-2026-12000 | 7.5 | 48.9 | — | Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive… |
| Vendor | CVEs |
|---|---|
| microsoft | 26 |
| siyuan-note | 26 |
| jenkins project | 20 |
| openclaw | 18 |
| red hat | 17 |
| getgrav | 15 |
| 15 | |
| jetbrains | 14 |
| open-webui | 14 |
| gitlab | 13 |
| jfrog | 12 |
| mervinpraison | 12 |
| sap_se | 12 |
| drupal | 10 |
| elastic | 10 |