boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-494

Weakness type CWE-494 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
16160

Monthly trend

▅▇▃█

2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-90898.823.9
CVE-2026-480469.319.8Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC H…
CVE-2026-556988.818.5pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc…
CVE-2026-90379.316.1Download of code without integrity check in XCharge C6
CVE-2026-663989.415.5phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
CVE-2026-450589.414.5electerm: Import unsafe bookmark data could lead to unsafe operation when click local t…
CVE-2026-556978.87.2pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-539707.56.8ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb
CVE-2026-492418.75.1Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS …
CVE-2026-505629.34.8FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
CVE-2021-479867.72.2Parse Server - Unreviewed Code Execution via Malicious Version Tags
CVE-2021-479877.72.2Parse Server - Arbitrary Code Execution via Malicious Version Tags
CVE-2026-134339.61.7IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-122595.31.0Improper Input Validation in nltk/nltk
CVE-2026-03927.30.0eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update
CVE-2026-762417.3stigmem Plugin Signature Enforcement Bypass via Configuration

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
parse-community2
pnpm2
angular1
connectwise1
eidetic-labs1
electerm1
ibm1
labring1
latvijas valsts radio un televīzijas centrs (lvrtc)1
lucasgelfond1
nltk1
thorsten1
truelockmc1
xcharge1