Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-88 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 68 | 67 | 0 |
▁▁▁▁▁▂▄▇█▇
2025-11 1 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 3 · 2026-05 9 · 2026-06 17 · 2026-07 19 · 2026-08 17
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-49373 | 8.8 | 96.0 | — | — |
| CVE-2026-61459 | 9.3 | 80.3 | — | MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools |
| CVE-2026-40047 | 9.1 | 76.5 | — | Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar… |
| CVE-2026-40079 | 8.6 | 64.0 | — | Cacti: Command Injection via escape_command() no-op in RRDtool execution |
| CVE-2026-40938 | 8.5 | 53.4 | — | Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Inje… |
| CVE-2026-47114 | 8.6 | 50.4 | — | IINA < 1.4.3 Command Execution via iina://open URL Scheme |
| CVE-2026-72538 | 8.8 | 50.1 | — | PrefectHQ Prefect - Argument Injection |
| CVE-2026-44790 | 9.4 | 48.2 | — | n8n: Arbitrary File Read via Git Node |
| CVE-2026-54088 | 9.3 | 47.5 | — | File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authent… |
| CVE-2026-31230 | 9.8 | 43.9 | — | — |
| CVE-2026-42266 | 8.8 | 43.9 | — | JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali… |
| CVE-2026-73240 | 9.8 | 43.2 | — | Apache Allura: Git command injection |
| CVE-2026-49987 | 7.5 | 43.1 | — | Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection |
| CVE-2026-44189 | 7.8 | 42.9 | — | Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code exe… |
| CVE-2026-57572 | 10.0 | 42.8 | — | Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.… |
| CVE-2025-61731 | 7.8 | 42.7 | — | Arbitrary file write using cgo pkg-config directive in cmd/go |
| CVE-2026-46529 | 8.4 | 42.5 | — | PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen |
| CVE-2026-53790 | 9.2 | 41.7 | — | rsync < 3.5.0 Command Injection via Multiple Code Paths |
| CVE-2024-52011 | 7.5 | 41.6 | — | launch-editor vulnerable to command injection via the crafted request on Windows |
| CVE-2026-52750 | 8.4 | 41.0 | — | Ghidra < 12.1- Command Injection via URL Annotation Click |
| Vendor | CVEs |
|---|---|
| gitpython-developers | 5 |
| red hat | 5 |
| apache | 2 |
| aws | 2 |
| cloudfoundry foundation | 2 |
| flux159 | 2 |
| prefecthq | 2 |
| prolix-oc | 2 |
| python software foundation | 2 |
| rsyncproject | 2 |
| apple | 1 |
| cacti | 1 |
| dbt-labs | 1 |
| dell | 1 |
| filebrowser | 1 |