Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-494
Weakness type CWE-494 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 48 | 46 | 4 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▃▂▇█▂
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 14 · 2026-09 16 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-40799 | 8.8 | 98.3 | KEV | D-Link DNR-322L |
| CVE-2025-15556 | 7.7 | 77.4 | KEV | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification |
| CVE-2021-44168 | 3.3 | 57.2 | KEV | Fortinet FortiOS |
| CVE-2026-3502 | 7.8 | 23.7 | KEV | TrueConf Client Update Integrity Verification Bypass |
| CVE-2026-85427 | 9.2 | 43.9 | — | MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MI… |
| CVE-2025-69263 | 7.5 | 38.9 | — | pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies |
| CVE-2026-30612 | 9.8 | 33.6 | — | — |
| CVE-2026-65081 | 9.8 | 33.0 | — | — |
| CVE-2026-48046 | 9.3 | 27.0 | — | Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC H… |
| CVE-2026-66398 | 9.4 | 25.5 | — | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
| CVE-2026-82021 | 9.0 | 25.0 | — | Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference |
| CVE-2026-59286 | 8.1 | 23.6 | — | Spring for GraphQL loads Untrusted Resources in GraphiQL support |
| CVE-2026-65097 | 8.8 | 22.2 | — | — |
| CVE-2026-63696 | 9.1 | 20.8 | — | — |
| CVE-2026-45058 | 9.4 | 20.4 | — | electerm: Import unsafe bookmark data could lead to unsafe operation when click local t… |
| CVE-2026-55698 | 8.8 | 20.3 | — | pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc… |
| CVE-2026-92128 | 7.5 | 19.8 | — | — |
| CVE-2026-79963 | 7.4 | 17.2 | — | — |
| CVE-2026-9037 | 9.3 | 16.8 | — | Download of code without integrity check in XCharge C6 |
| CVE-2026-53970 | 7.5 | 15.4 | — | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 4 |
| jenkins project | 3 |
| pnpm | 3 |
| nvidia | 2 |
| parse-community | 2 |
| angular | 1 |
| asus | 1 |
| connectwise | 1 |
| eidetic-labs | 1 |
| electerm | 1 |
| fortinet | 1 |
| hclsoftware | 1 |
| hugging face | 1 |
| ibm | 1 |
| jetbrains | 1 |