boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-116

Weakness type CWE-116 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
85832

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂█▆▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 3 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 30 · 2026-07 22 · 2026-08 21

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-246826.198.1KEVSynacor Zimbra Collaborate Suite (ZCS)
CVE-2026-202457.897.8KEVCisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
CVE-2026-483589.171.9Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)
CVE-2026-563799.256.4ImageMagick - Command Injection via SVG Decoder
CVE-2026-257558.854.9jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
CVE-2026-120448.750.7pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog t…
CVE-2025-17952.346.3Mishandling of comma during folding and unicode-encoding of email headers
CVE-2026-498446.344.9Apache Log4j API: Improper serialization of non-finite floating-point values in MapMess…
CVE-2026-734178.643.8JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2026-506596.543.6.NET Spoofing Vulnerability
CVE-2026-247378.142.3jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Exec…
CVE-2026-483765.441.0ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
CVE-2026-36446.039.4Incomplete control character validation in http.cookies
CVE-2026-621848.737.2luci-app-banip Log Monitor IP Extraction Bypass
CVE-2026-546997.736.5Warp: OS command injection when opening terminal links from WSL
CVE-2025-516779.136.1
CVE-2026-259408.135.6jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioBu…
CVE-2026-598338.632.1SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lut…
CVE-2026-449135.231.9Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVE-2026-439716.330.4Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
orval-labs7
duck-organization5
parallax4
misp3
pgadmin.org3
adobe2
apache2
ericcornelissen2
honojs2
loytec2
python software foundation2
siyuan-note2
twigphp2
@swc1
apostrophecms1