Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-93 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 61 | 59 | 1 |
▁▁▁▁▁▁▁▁▁▄█▅▅
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 14 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2026-72590 | 9.8 | 67.7 | — | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter |
| CVE-2026-12357 | 7.2 | 62.7 | — | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution V… |
| CVE-2026-42578 | 2.9 | 62.0 | — | Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| CVE-2026-15429 | 5.1 | 55.1 | — | Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v |
| CVE-2026-42258 | 5.8 | 53.2 | — | net-imap: Command Injection via unvalidated Symbol inputs |
| CVE-2026-45067 | 6.3 | 47.0 | — | Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address |
| CVE-2026-57281 | 7.5 | 45.8 | — | — |
| CVE-2026-11373 | 9.1 | 44.6 | — | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections |
| CVE-2026-1502 | 5.7 | 44.3 | — | HTTP client proxy tunnel headers not validated for CR/LF |
| CVE-2026-47072 | 6.9 | 43.2 | — | CRLF injection in WebSocket upgrade request in hackney |
| CVE-2026-12143 | 8.7 | 42.9 | — | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje… |
| CVE-2026-47240 | 5.8 | 40.2 | — | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
| CVE-2026-47075 | 6.8 | 39.5 | — | CR/LF injection in query parameter in hackney |
| CVE-2026-50629 | 5.3 | 38.9 | — | Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier |
| CVE-2026-59921 | 6.5 | 38.6 | — | Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| CVE-2026-11362 | 9.8 | 37.3 | — | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags |
| CVE-2026-47069 | 2.1 | 35.7 | — | CRLF injection in cookie domain/path options in hackney |
| CVE-2025-8419 | 5.3 | 34.7 | — | Org.keycloak/keycloak-services: keycloak smtp inject vulnerability |
| CVE-2026-53533 | 6.9 | 31.8 | — | aiosmtplib: SMTP command injection via CR/LF in sender/recipient address |
| Vendor | CVEs |
|---|---|
| netty | 4 |
| benoitc | 3 |
| pevans | 3 |
| red hat | 3 |
| ruby | 3 |
| binary | 2 |
| guzzle | 2 |
| joomla! project | 2 |
| symfony | 2 |
| undici | 2 |
| aio-libs | 1 |
| alseambusher | 1 |
| apache | 1 |
| bdthemes | 1 |
| boringproxy | 1 |