Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-434
Weakness type CWE-434 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 468 | 431 | 27 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▇██▂
2025-11 1 · 2025-12 1 · 2026-01 2 · 2026-02 3 · 2026-03 5 · 2026-04 3 · 2026-05 27 · 2026-06 70 · 2026-07 91 · 2026-08 114 · 2026-09 106 · 2026-10 10
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-12617 | 8.1 | 100.0 | KEV | Apache Tomcat |
| CVE-2018-15961 | 9.8 | 100.0 | KEV | Adobe ColdFusion |
| CVE-2021-31207 | 6.6 | 100.0 | KEV | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2017-12615 | 8.1 | 99.9 | KEV | Apache Tomcat |
| CVE-2025-31324 | 9.8 | 99.9 | KEV | Missing Authorization check in SAP NetWeaver (Visual Composer development server) |
| CVE-2024-50623 | 9.8 | 99.9 | KEV | Cleo Multiple Products |
| CVE-2016-3088 | 9.8 | 99.9 | KEV | Apache ActiveMQ |
| CVE-2020-25213 | 10.0 | 99.9 | KEV | WordPress File Manager Plugin |
| CVE-2020-8260 | 7.2 | 99.9 | KEV | Ivanti Pulse Connect Secure |
| CVE-2024-7399 | 9.8 | 99.8 | KEV | Samsung MagicINFO 9 Server |
| CVE-2026-48908 | 10.0 | 99.8 | KEV | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension f… |
| CVE-2025-52691 | 10.0 | 99.7 | KEV | Upload Arbitrary Files |
| CVE-2017-11357 | 9.8 | 99.6 | KEV | Telerik User Interface (UI) for ASP.NET AJAX |
| CVE-2019-8394 | 7.5 | 99.2 | KEV | Zoho ManageEngine |
| CVE-2021-27860 | 9.8 | 98.6 | KEV | Arbitrary file upload vulnerability in FatPipe software |
| CVE-2021-26828 | 8.8 | 98.6 | KEV | OpenPLC ScadaBR |
| CVE-2020-13671 | 8.8 | 98.4 | KEV | Drupal Drupal core |
| CVE-2024-57968 | 9.9 | 98.3 | KEV | Advantive VeraCore |
| CVE-2026-56290 | 10.0 | 98.2 | KEV | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extensi… |
| CVE-2018-4063 | 8.8 | 98.0 | KEV | Sierra Wireless AirLink ALEOS |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| sourcecodester | 13 |
| themagnifico52 | 7 |
| d-link | 6 |
| microsoft | 6 |
| apache | 5 |
| dell | 5 |
| itsourcecode | 5 |
| adobe | 4 |
| kiteworks | 3 |
| parse-community | 3 |
| phreesoft | 3 |
| plank | 3 |
| progress | 3 |
| altium | 2 |
| balbooa.com | 2 |