Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-20 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 921 | 843 | 13 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▆▄
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 1 · 2026-01 6 · 2026-02 3 · 2026-03 7 · 2026-04 16 · 2026-05 55 · 2026-06 360 · 2026-07 267 · 2026-08 129
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | KEV | Apache Log4j2 |
| CVE-2021-21985 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2020-3452 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2018-0296 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance (ASA) |
| CVE-2022-47966 | 9.8 | 100.0 | KEV | Zoho ManageEngine |
| CVE-2026-34197 | 8.8 | 99.9 | KEV | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could… |
| CVE-2024-21413 | 9.8 | 99.9 | KEV | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-34910 | 10.0 | 99.7 | KEV | Ubiquiti UniFi OS |
| CVE-2022-29499 | 9.8 | 99.0 | KEV | Mitel MiVoice Connect |
| CVE-2026-12569 | 9.3 | 98.1 | KEV | Remote Code Execution (RCE) vulnerability in Windchill PDMlink |
| CVE-2018-19949 | 9.8 | 97.7 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2026-32201 | 6.5 | 97.5 | KEV | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2015-2291 | 7.8 | 94.8 | KEV | Intel Ethernet Diagnostics Driver for Windows |
| CVE-2023-36899 | 8.8 | 99.5 | — | ASP.NET Elevation of Privilege Vulnerability |
| CVE-2023-21818 | 7.5 | 98.6 | — | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2024-30087 | 7.8 | 95.0 | — | Win32k Elevation of Privilege Vulnerability |
| CVE-2024-38244 | 7.8 | 92.9 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
| CVE-2024-38241 | 7.8 | 92.8 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
| CVE-2024-30078 | 8.8 | 91.8 | — | Windows Wi-Fi Driver Remote Code Execution Vulnerability |
| CVE-2026-48284 | 9.6 | 91.4 | — | ColdFusion | Improper Input Validation (CWE-20) |
| Vendor | CVEs |
|---|---|
| 335 | |
| microsoft | 116 |
| apache | 44 |
| adobe | 26 |
| netgear | 18 |
| oracle | 18 |
| apple | 17 |
| red hat | 11 |
| samsung mobile | 9 |
| ubiquiti | 8 |
| unisoc (shanghai) technologies co | 8 |
| tobit laboratories | 7 |
| cisco | 6 |
| splunk | 5 |
| tp-link systems | 5 |