boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-434

Weakness type CWE-434 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2762629

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▆

2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 4 · 2026-04 3 · 2026-05 27 · 2026-06 70 · 2026-07 91 · 2026-08 65

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2017-126158.199.9KEVApache Tomcat
CVE-2025-313249.899.9KEVMissing Authorization check in SAP NetWeaver (Visual Composer development server)
CVE-2024-506239.899.9KEVCleo Multiple Products
CVE-2026-4890810.099.8KEVJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension f…
CVE-2026-5629010.099.7KEVJoomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extensi…
CVE-2026-4893910.099.6KEVJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Jooml…
CVE-2026-5629110.099.5KEVJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension…
CVE-2017-113579.899.5KEVTelerik User Interface (UI) for ASP.NET AJAX
CVE-2021-200227.296.7KEVSonicWall SonicWall Email Security
CVE-2018-92069.899.9
CVE-2026-483569.398.0Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVE-2025-10258.797.2
CVE-2019-108698.194.3
CVE-2026-537879.391.8Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
CVE-2026-4827610.091.6ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVE-2026-148949.885.3Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (da…
CVE-2026-144839.881.0Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File…
CVE-2026-584809.278.6Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
CVE-2025-341219.375.1Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
CVE-2026-5782710.073.9Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
sourcecodester10
d-link6
themagnifico525
apache4
adobe3
parse-community3
phreesoft3
altium2
balbooa.com2
code-projects2
codeigniter42
coderevolution2
dataease2
dell2
dj-extensions.com2