Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-116 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 85 | 83 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂█▆▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 3 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 30 · 2026-07 22 · 2026-08 21
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-24682 | 6.1 | 98.1 | KEV | Synacor Zimbra Collaborate Suite (ZCS) |
| CVE-2026-20245 | 7.8 | 97.8 | KEV | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability |
| CVE-2026-48358 | 9.1 | 71.9 | — | Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-56379 | 9.2 | 56.4 | — | ImageMagick - Command Injection via SVG Decoder |
| CVE-2026-25755 | 8.8 | 54.9 | — | jsPDF has PDF Object Injection via Unsanitized Input in addJS Method |
| CVE-2026-12044 | 8.7 | 50.7 | — | pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog t… |
| CVE-2025-1795 | 2.3 | 46.3 | — | Mishandling of comma during folding and unicode-encoding of email headers |
| CVE-2026-49844 | 6.3 | 44.9 | — | Apache Log4j API: Improper serialization of non-finite floating-point values in MapMess… |
| CVE-2026-73417 | 8.6 | 43.8 | — | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) |
| CVE-2026-50659 | 6.5 | 43.6 | — | .NET Spoofing Vulnerability |
| CVE-2026-24737 | 8.1 | 42.3 | — | jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Exec… |
| CVE-2026-48376 | 5.4 | 41.0 | — | ColdFusion | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-3644 | 6.0 | 39.4 | — | Incomplete control character validation in http.cookies |
| CVE-2026-62184 | 8.7 | 37.2 | — | luci-app-banip Log Monitor IP Extraction Bypass |
| CVE-2026-54699 | 7.7 | 36.5 | — | Warp: OS command injection when opening terminal links from WSL |
| CVE-2025-51677 | 9.1 | 36.1 | — | — |
| CVE-2026-25940 | 8.1 | 35.6 | — | jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioBu… |
| CVE-2026-59833 | 8.6 | 32.1 | — | SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lut… |
| CVE-2026-44913 | 5.2 | 31.9 | — | Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL |
| CVE-2026-43971 | 6.3 | 30.4 | — | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 |
| Vendor | CVEs |
|---|---|
| orval-labs | 7 |
| duck-organization | 5 |
| parallax | 4 |
| misp | 3 |
| pgadmin.org | 3 |
| adobe | 2 |
| apache | 2 |
| ericcornelissen | 2 |
| honojs | 2 |
| loytec | 2 |
| python software foundation | 2 |
| siyuan-note | 2 |
| twigphp | 2 |
| @swc | 1 |
| apostrophecms | 1 |