Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-20
Weakness type CWE-20 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1383 | 1239 | 71 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▆▆▆▁
2025-11 0 · 2025-12 4 · 2026-01 9 · 2026-02 5 · 2026-03 10 · 2026-04 21 · 2026-05 64 · 2026-06 360 · 2026-07 267 · 2026-08 247 · 2026-09 253 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other J… |
| CVE-2024-3400 | 10.0 | 100.0 | KEV | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalPr… |
| CVE-2021-21985 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2020-3452 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Se… |
| CVE-2018-7600 | 9.8 | 100.0 | KEV | Drupal Drupal Core |
| CVE-2019-0604 | 9.8 | 100.0 | KEV | Microsoft SharePoint |
| CVE-2018-0296 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance (ASA) |
| CVE-2022-47966 | 9.8 | 100.0 | KEV | Zoho ManageEngine |
| CVE-2018-0171 | 7.5 | 99.9 | KEV | Cisco IOS and IOS XE |
| CVE-2017-0148 | 8.1 | 99.9 | KEV | Microsoft SMBv1 server |
| CVE-2022-24086 | 9.8 | 99.9 | KEV | Adobe Commerce checkout improper input validation leads to remote code execution |
| CVE-2023-22515 | 10.0 | 99.9 | KEV | Atlassian Confluence Data Center and Server |
| CVE-2017-3881 | 9.8 | 99.9 | KEV | Cisco IOS and IOS XE |
| CVE-2017-9791 | 9.8 | 99.9 | KEV | Apache Struts 1 |
| CVE-2017-15944 | 9.8 | 99.9 | KEV | Palo Alto Networks PAN-OS |
| CVE-2016-3714 | 8.4 | 99.9 | KEV | ImageMagick ImageMagick |
| CVE-2023-23397 | 9.8 | 99.9 | KEV | Microsoft Outlook Elevation of Privilege Vulnerability |
| CVE-2020-1350 | 10.0 | 99.9 | KEV | Microsoft Windows |
| CVE-2019-1652 | 7.2 | 99.9 | KEV | Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability |
| CVE-2024-21413 | 9.8 | 99.9 | KEV | Microsoft Outlook Remote Code Execution Vulnerability |