Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-122
Weakness type CWE-122 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1213 | 1099 | 21 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▅█▁
2025-11 1 · 2025-12 1 · 2026-01 14 · 2026-02 12 · 2026-03 5 · 2026-04 24 · 2026-05 65 · 2026-06 112 · 2026-07 196 · 2026-08 224 · 2026-09 443 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2015-3113 | 7.8 | 100.0 | KEV | Adobe Flash Player |
| CVE-2009-3459 | 8.8 | 99.7 | KEV | Adobe Acrobat and Reader |
| CVE-2021-21017 | 8.8 | 99.7 | KEV | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code… |
| CVE-2023-27997 | 9.8 | 99.7 | KEV | Fortinet FortiOS and FortiProxy SSL-VPN |
| CVE-2023-4911 | 7.8 | 99.6 | KEV | Glibc: buffer overflow in ld.so leading to privilege escalation |
| CVE-2024-38812 | 9.8 | 99.0 | KEV | Heap-overflow vulnerability |
| CVE-2023-28252 | 7.8 | 98.8 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2019-3568 | 9.8 | 98.2 | KEV | Meta Platforms WhatsApp |
| CVE-2024-49138 | 7.8 | 97.9 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2023-36036 | 7.8 | 96.9 | KEV | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2023-23376 | 7.8 | 95.7 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2025-21333 | 7.8 | 95.5 | KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
| CVE-2020-16010 | 9.6 | 93.5 | KEV | Google Chrome for Android UI |
| CVE-2024-30051 | 7.8 | 92.7 | KEV | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2025-25249 | 9.8 | 89.9 | KEV | — |
| CVE-2025-24985 | 7.8 | 89.8 | KEV | Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
| CVE-2026-85880 | 7.8 | 89.2 | KEV | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
| CVE-2026-94127 | 9.3 | 82.1 | KEV | BIG-IP APM OAuth vulnerability |
| CVE-2025-24993 | 7.8 | 81.7 | KEV | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2025-21418 | 7.8 | 74.5 | KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 696 |
| 76 | |
| adobe | 56 |
| red hat | 26 |
| wireshark foundation | 21 |
| ibm | 14 |
| freerdp | 13 |
| apache | 10 |
| academysoftwarefoundation | 8 |
| f5 | 7 |
| ffmpeg | 7 |
| freebsd | 6 |
| gnu | 6 |
| imagemagick | 6 |
| mediatek | 6 |