Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-90 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 20 | 0 |
▂▁▁▂▄▆█▄
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 3
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42568 | 4.3 | 60.9 | — | Yamcs Vulnerable to LDAP Injection in LdapAuthModule |
| CVE-2026-58222 | 8.8 | 55.0 | — | Samba: samba ad ldap compare filter injection and trusted-request confusion disclose pr… |
| CVE-2026-44617 | 6.5 | 55.0 | — | Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 |
| CVE-2026-47303 | 8.8 | 51.6 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-44930 | 9.8 | 50.1 | — | Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository |
| CVE-2026-11770 | 7.5 | 49.9 | — | 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check |
| CVE-2026-1498 | 7.0 | 49.6 | — | WatchGuard Firebox LDAP Injection |
| CVE-2026-11748 | 6.9 | 46.9 | — | — |
| CVE-2026-46745 | 5.3 | 44.9 | — | Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap rea… |
| CVE-2026-0636 | 5.5 | 42.4 | — | LDAP Injection Vulnerability in LDAPStoreHelper.java |
| CVE-2026-49268 | 8.8 | 40.4 | — | Apache Shiro: LDAP DN Injection in DefaultLdapRealm |
| CVE-2026-44616 | 6.5 | 37.5 | — | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction |
| CVE-2026-13696 | 8.8 | 28.7 | — | LDAP Injection in HAVELSAN's Liman MYS |
| CVE-2026-59652 | 6.9 | 27.2 | — | LDAP filter injection in legacy jdk1.4 LDAPStoreHelper |
| CVE-2026-19930 | 2.1 | 15.7 | — | Dolibarr User Cloning card.php ldap injection |
| CVE-2026-45559 | 4.9 | 14.6 | — | Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only) |
| CVE-2026-57288 | 3.7 | 13.3 | — | — |
| CVE-2026-4256 | 8.2 | 11.9 | — | LDAP Injection in PEAKUP's PassGate |
| CVE-2026-44063 | 4.2 | 11.9 | — | LDAP filter injection |
| CVE-2026-74241 | 4.8 | 8.2 | — | Quay: ldap referral filter injection in quay external ldap authentication |
| Vendor | CVEs |
|---|---|
| apache | 5 |
| red hat | 3 |
| legion of the bouncy castle | 2 |
| havelsan | 1 |
| jenkins project | 1 |
| ly | 1 |
| microsoft | 1 |
| netatalk | 1 |
| peakup technology | 1 |
| roxy-wi | 1 |
| watchguard | 1 |
| yamcs | 1 |