Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-22
Weakness type CWE-22 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1726 | 1616 | 85 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆▆██▂
2025-11 0 · 2025-12 8 · 2026-01 8 · 2026-02 6 · 2026-03 16 · 2026-04 14 · 2026-05 80 · 2026-06 280 · 2026-07 316 · 2026-08 428 · 2026-09 432 · 2026-10 36
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-11510 | 9.9 | 100.0 | KEV | Ivanti Pulse Connect Secure |
| CVE-2019-19781 | 9.8 | 100.0 | KEV | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance |
| CVE-2020-5902 | 9.8 | 100.0 | KEV | F5 BIG-IP |
| CVE-2021-22005 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2022-29464 | 9.8 | 100.0 | KEV | WSO2 Multiple Products |
| CVE-2018-13379 | 9.1 | 100.0 | KEV | Fortinet FortiOS |
| CVE-2023-32315 | 8.6 | 100.0 | KEV | Openfire administration console authentication bypass |
| CVE-2021-26086 | 5.3 | 100.0 | KEV | Atlassian Jira Server and Data Center |
| CVE-2021-41773 | 7.5 | 100.0 | KEV | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
| CVE-2021-20090 | 9.8 | 100.0 | KEV | Arcadyan Buffalo Firmware |
| CVE-2021-42013 | 9.8 | 100.0 | KEV | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incom… |
| CVE-2024-32113 | 9.1 | 100.0 | KEV | Apache OFBiz: Path traversal leading to RCE |
| CVE-2019-3396 | 9.8 | 100.0 | KEV | Atlassian Confluence Server and Data Server |
| CVE-2021-27065 | 7.8 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-21972 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2010-2861 | 9.8 | 100.0 | KEV | Adobe ColdFusion |
| CVE-2024-28995 | 8.6 | 99.9 | KEV | SolarWinds Serv-U L Directory Transversal Vulnerability |
| CVE-2024-4885 | 9.8 | 99.9 | KEV | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability |
| CVE-2022-30333 | 7.5 | 99.9 | KEV | RARLAB UnRAR |
| CVE-2019-16278 | 9.8 | 99.9 | KEV | Nostromo nhttpd |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 69 |
| red hat | 31 |
| microsoft | 28 |
| apache | 27 |
| apple | 25 |
| adobe | 22 |
| sooperset | 15 |
| mervinpraison | 14 |
| dell | 12 |
| eclipse foundation | 10 |
| siyuan-note | 10 |
| altium | 9 |
| cisco | 9 |
| pnpm | 9 |
| python software foundation | 9 |