boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-116

Weakness type CWE-116 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1381344

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▇▅██▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 3 · 2026-03 3 · 2026-04 0 · 2026-05 5 · 2026-06 30 · 2026-07 22 · 2026-08 36 · 2026-09 34 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-384759.1100.0KEVApache HTTP Server weakness in mod_rewrite when first segment of substitution matches f…
CVE-2022-246826.198.2KEVSynacor Zimbra Collaborate Suite (ZCS)
CVE-2026-202457.897.9KEVCisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
CVE-2022-429489.885.5KEVFortra Cobalt Strike
CVE-2026-563799.275.6—ImageMagick - Command Injection via SVG Decoder
CVE-2026-483589.167.3—Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)
CVE-2026-498446.355.5—Apache Log4j API: Improper serialization of non-finite floating-point values in MapMess…
CVE-2026-257558.855.1—jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
CVE-2026-945455.354.9—Satori-generated SVG has improper escaping
CVE-2026-621848.754.5—luci-app-banip Log Monitor IP Extraction Bypass
CVE-2026-541828.154.4—backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled H…
CVE-2026-734178.653.3—JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2026-546997.753.0—Warp: OS command injection when opening terminal links from WSL
CVE-2026-506596.552.9—.NET Spoofing Vulnerability
CVE-2026-120448.751.9—pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog t…
CVE-2026-827566.350.7—ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authe…
CVE-2026-483765.450.7—ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
CVE-2026-909999.850.3—Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileg…
CVE-2026-626819.349.5—Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
CVE-2026-626829.349.5—Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrl…

Most-affected vendors