Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-434 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 276 | 262 | 9 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▆
2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 4 · 2026-04 3 · 2026-05 27 · 2026-06 70 · 2026-07 91 · 2026-08 65
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-12615 | 8.1 | 99.9 | KEV | Apache Tomcat |
| CVE-2025-31324 | 9.8 | 99.9 | KEV | Missing Authorization check in SAP NetWeaver (Visual Composer development server) |
| CVE-2024-50623 | 9.8 | 99.9 | KEV | Cleo Multiple Products |
| CVE-2026-48908 | 10.0 | 99.8 | KEV | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension f… |
| CVE-2026-56290 | 10.0 | 99.7 | KEV | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extensi… |
| CVE-2026-48939 | 10.0 | 99.6 | KEV | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Jooml… |
| CVE-2026-56291 | 10.0 | 99.5 | KEV | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension… |
| CVE-2017-11357 | 9.8 | 99.5 | KEV | Telerik User Interface (UI) for ASP.NET AJAX |
| CVE-2021-20022 | 7.2 | 96.7 | KEV | SonicWall SonicWall Email Security |
| CVE-2018-9206 | 9.8 | 99.9 | — | — |
| CVE-2026-48356 | 9.3 | 98.0 | — | Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) |
| CVE-2025-1025 | 8.7 | 97.2 | — | — |
| CVE-2019-10869 | 8.1 | 94.3 | — | — |
| CVE-2026-53787 | 9.3 | 91.8 | — | Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload |
| CVE-2026-48276 | 10.0 | 91.6 | — | ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) |
| CVE-2026-14894 | 9.8 | 85.3 | — | Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (da… |
| CVE-2026-14483 | 9.8 | 81.0 | — | Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File… |
| CVE-2026-58480 | 9.2 | 78.6 | — | Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments |
| CVE-2025-34121 | 9.3 | 75.1 | — | Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE |
| CVE-2026-57827 | 10.0 | 73.9 | — | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.… |
| Vendor | CVEs |
|---|---|
| sourcecodester | 10 |
| d-link | 6 |
| themagnifico52 | 5 |
| apache | 4 |
| adobe | 3 |
| parse-community | 3 |
| phreesoft | 3 |
| altium | 2 |
| balbooa.com | 2 |
| code-projects | 2 |
| codeigniter4 | 2 |
| coderevolution | 2 |
| dataease | 2 |
| dell | 2 |
| dj-extensions.com | 2 |