Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-943 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 22 | 0 |
▂█▅▅
2026-05 1 · 2026-06 10 · 2026-07 6 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-10698 | 7.2 | 40.5 | — | Table scope bypass vulnerability in custom reports |
| CVE-2026-40141 | 8.5 | 40.4 | — | High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support … |
| CVE-2026-54350 | 9.8 | 38.9 | — | Budibase: Anonymous NoSQL operator injection via published-app query templates |
| CVE-2026-44840 | 7.5 | 30.1 | — | Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query |
| CVE-2026-53674 | 7.1 | 29.9 | — | BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution |
| CVE-2026-54019 | 6.5 | 26.5 | — | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode |
| CVE-2026-46591 | 8.2 | 25.8 | — | Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties heade… |
| CVE-2026-45689 | 9.1 | 23.5 | — | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary Use… |
| CVE-2026-47835 | 7.5 | 23.1 | — | Spring AI vector store metadata filtering to handle special characters in Elasticsearch… |
| CVE-2026-40102 | 6.5 | 22.2 | — | Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics |
| CVE-2026-73618 | 8.7 | 21.6 | — | Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter |
| CVE-2026-45688 | 9.1 | 21.5 | — | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAM… |
| CVE-2025-60357 | 8.1 | 20.5 | — | — |
| CVE-2026-41696 | 5.9 | 18.2 | — | Spring Data MongoDB Bind Parameter Literal Quoting Breakout |
| CVE-2026-8649 | 9.8 | 17.7 | — | Institution scope bypass vulnerability in custom reports |
| CVE-2026-47181 | 8.7 | 16.8 | — | PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover |
| CVE-2026-63637 | 8.6 | 15.5 | — | Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter |
| CVE-2026-48121 | 6.7 | 14.0 | — | @langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allo… |
| CVE-2026-41697 | 4.8 | 13.8 | — | Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern |
| CVE-2026-73617 | 7.1 | 10.5 | — | Budibase before 3.40.0 NoSQL Injection via MongoDB datasource |
| Vendor | CVEs |
|---|---|
| budibase | 3 |
| spring | 3 |
| dgraph-io | 2 |
| progress | 2 |
| rocketchat | 2 |
| apache | 1 |
| ash-project | 1 |
| beyondtrust | 1 |
| buddypress | 1 |
| langchain-ai | 1 |
| macwarrior | 1 |
| makeplane | 1 |
| open-webui | 1 |
| penguinmod | 1 |