boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1395

Weakness type CWE-1395 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

█▆▃▃▆▁

2026-05 3 · 2026-06 2 · 2026-07 1 · 2026-08 1 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-346527.558.4—Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
CVE-2026-346545.355.1—Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
CVE-2026-585869.849.3—Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
CVE-2026-697134.426.7—Windows Secure Boot Security Feature Bypass Vulnerability
CVE-2026-582356.320.1—Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
CVE-2026-479068.619.9—Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
CVE-2026-904556.38.8—Dependency on vulnerable third-party component in Malcolm
CVE-2025-319739.86.6—HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of…
CVE-2024-422063.13.7—HCL iReflection Use of Third party vulnerable and outdated components issue was detecte…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
adobe3
hcl2
cisa1
microsoft1
sap_se1
zapad1