boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-20

Weakness type CWE-20 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1383123971

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▆▆▆▁

2025-11 0 · 2025-12 4 · 2026-01 9 · 2026-02 5 · 2026-03 10 · 2026-04 21 · 2026-05 64 · 2026-06 360 · 2026-07 267 · 2026-08 247 · 2026-09 253 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-4422810.0100.0KEVApache Log4j2 JNDI features do not protect against attacker controlled LDAP and other J…
CVE-2024-340010.0100.0KEVPAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalPr…
CVE-2021-219859.8100.0KEVVMware vCenter Server
CVE-2020-34527.5100.0KEVCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Se…
CVE-2018-76009.8100.0KEVDrupal Drupal Core
CVE-2019-06049.8100.0KEVMicrosoft SharePoint
CVE-2018-02967.5100.0KEVCisco Adaptive Security Appliance (ASA)
CVE-2022-479669.8100.0KEVZoho ManageEngine
CVE-2018-01717.599.9KEVCisco IOS and IOS XE
CVE-2017-01488.199.9KEVMicrosoft SMBv1 server
CVE-2022-240869.899.9KEVAdobe Commerce checkout improper input validation leads to remote code execution
CVE-2023-2251510.099.9KEVAtlassian Confluence Data Center and Server
CVE-2017-38819.899.9KEVCisco IOS and IOS XE
CVE-2017-97919.899.9KEVApache Struts 1
CVE-2017-159449.899.9KEVPalo Alto Networks PAN-OS
CVE-2016-37148.499.9KEVImageMagick ImageMagick
CVE-2023-233979.899.9KEVMicrosoft Outlook Elevation of Privilege Vulnerability
CVE-2020-135010.099.9KEVMicrosoft Windows
CVE-2019-16527.299.9KEVCisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
CVE-2024-214139.899.9KEVMicrosoft Outlook Remote Code Execution Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google416
microsoft149
adobe58
apache56
apple26
ubiquiti20
misp19
netgear19
oracle19
samsung mobile16
red hat13
pmmp11
cisco9
nvidia9
splunk9