Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-22 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1012 | 970 | 26 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▇
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 3 · 2026-01 8 · 2026-02 2 · 2026-03 8 · 2026-04 10 · 2026-05 76 · 2026-06 280 · 2026-07 316 · 2026-08 270
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-19781 | 9.8 | 100.0 | KEV | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance |
| CVE-2020-3452 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2021-27065 | 7.8 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2018-0296 | 7.5 | 100.0 | KEV | Cisco Adaptive Security Appliance (ASA) |
| CVE-2010-2861 | 9.8 | 100.0 | KEV | Adobe ColdFusion |
| CVE-2021-21972 | 9.8 | 99.9 | KEV | VMware vCenter Server |
| CVE-2026-48282 | 10.0 | 99.9 | KEV | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Travers… |
| CVE-2022-30333 | 7.5 | 99.9 | KEV | RARLAB UnRAR |
| CVE-2023-47246 | 9.8 | 99.9 | KEV | SysAid SysAid Server |
| CVE-2022-27925 | 7.2 | 99.9 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2024-41713 | 9.1 | 99.9 | KEV | Mitel MiCollab |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2021-40444 | 8.8 | 99.9 | KEV | Microsoft MSHTML Remote Code Execution Vulnerability |
| CVE-2018-20250 | 7.8 | 99.9 | KEV | RARLAB WinRAR |
| CVE-2024-57727 | 7.5 | 99.9 | KEV | SimpleHelp SimpleHelp |
| CVE-2022-37042 | 9.8 | 99.8 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2024-1708 | 8.4 | 99.7 | KEV | Improper limitation of a pathname to a restricted directory (“path traversal”) |
| CVE-2023-41266 | 6.5 | 99.6 | KEV | Qlik Sense |
| CVE-2026-34909 | 10.0 | 99.2 | KEV | Ubiquiti UniFi OS |
| CVE-2021-20023 | 4.9 | 98.8 | KEV | SonicWall SonicWall Email Security |
| Vendor | CVEs |
|---|---|
| ibm | 32 |
| apache | 18 |
| microsoft | 18 |
| adobe | 14 |
| red hat | 14 |
| altium | 9 |
| apple | 8 |
| mervinpraison | 8 |
| dell | 7 |
| python software foundation | 7 |
| ubiquiti | 7 |
| cisco | 6 |
| eclipse foundation | 6 |
| pnpm | 6 |
| progress | 6 |