boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-502

Weakness type CWE-502 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
79171174

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▇▅▆█▁

2025-11 0 · 2025-12 2 · 2026-01 4 · 2026-02 4 · 2026-03 7 · 2026-04 12 · 2026-05 29 · 2026-06 183 · 2026-07 125 · 2026-08 144 · 2026-09 198 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-4422810.0100.0KEVApache Log4j2 JNDI features do not protect against attacker controlled LDAP and other J…
CVE-2021-354649.8100.0KEVForgeRock Access Management (AM)
CVE-2023-06697.2100.0KEVFortra GoAnywhere MFT License Response Servlet Command Injection
CVE-2025-537709.8100.0KEVMicrosoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-293009.8100.0KEVAdobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CVE-2025-592879.8100.0KEVWindows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2022-410828.0100.0KEVMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-479869.8100.0KEVIBM Aspera Faspex code execution
CVE-2018-26289.8100.0KEVOracle WebLogic Server
CVE-2020-101899.8100.0KEVZoho ManageEngine
CVE-2025-2481310.0100.0KEVApache Tomcat: Potential RCE and/or information disclosure and/or information corruptio…
CVE-2022-354059.8100.0KEVZoho ManageEngine
CVE-2020-79619.8100.0KEVLiferay Liferay Portal
CVE-2023-4660410.0100.0KEVApache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization caus…
CVE-2025-5518210.0100.0KEVMeta React Server Components
CVE-2025-100359.8100.0KEVDeserialization Vulnerability in GoAnywhere MFT's License Servlet
CVE-2019-189359.8100.0KEVProgress Telerik UI for ASP.NET AJAX
CVE-2017-10003539.8100.0KEVJenkins Jenkins
CVE-2017-98058.199.9KEVApache Struts
CVE-2020-06188.899.9KEVMicrosoft SQL Server

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft71
nvidia55
apache41
picklescan36
ibm25
oracle16
spring14
elated-themes11
red hat9
crm perks8
jenkins project8
mikado-themes8
adobe7
cisco7
themerex7