boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-20

Weakness type CWE-20 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
92184313

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▆▄

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 1 · 2026-01 6 · 2026-02 3 · 2026-03 7 · 2026-04 16 · 2026-05 55 · 2026-06 360 · 2026-07 267 · 2026-08 129

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-4422810.0100.0KEVApache Log4j2
CVE-2021-219859.8100.0KEVVMware vCenter Server
CVE-2020-34527.5100.0KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2018-02967.5100.0KEVCisco Adaptive Security Appliance (ASA)
CVE-2022-479669.8100.0KEVZoho ManageEngine
CVE-2026-341978.899.9KEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could…
CVE-2024-214139.899.9KEVMicrosoft Outlook Remote Code Execution Vulnerability
CVE-2026-3491010.099.7KEVUbiquiti UniFi OS
CVE-2022-294999.899.0KEVMitel MiVoice Connect
CVE-2026-125699.398.1KEVRemote Code Execution (RCE) vulnerability in Windchill PDMlink
CVE-2018-199499.897.7KEVQNAP Network Attached Storage (NAS)
CVE-2026-322016.597.5KEVMicrosoft SharePoint Server Spoofing Vulnerability
CVE-2015-22917.894.8KEVIntel Ethernet Diagnostics Driver for Windows
CVE-2023-368998.899.5ASP.NET Elevation of Privilege Vulnerability
CVE-2023-218187.598.6Windows Secure Channel Denial of Service Vulnerability
CVE-2024-300877.895.0Win32k Elevation of Privilege Vulnerability
CVE-2024-382447.892.9Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-382417.892.8Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-300788.891.8Windows Wi-Fi Driver Remote Code Execution Vulnerability
CVE-2026-482849.691.4ColdFusion | Improper Input Validation (CWE-20)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google335
microsoft116
apache44
adobe26
netgear18
oracle18
apple17
red hat11
samsung mobile9
ubiquiti8
unisoc (shanghai) technologies co8
tobit laboratories7
cisco6
splunk5
tp-link systems5