Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-502
Weakness type CWE-502 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 791 | 711 | 74 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▇▅▆█▁
2025-11 0 · 2025-12 2 · 2026-01 4 · 2026-02 4 · 2026-03 7 · 2026-04 12 · 2026-05 29 · 2026-06 183 · 2026-07 125 · 2026-08 144 · 2026-09 198 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other J… |
| CVE-2021-35464 | 9.8 | 100.0 | KEV | ForgeRock Access Management (AM) |
| CVE-2023-0669 | 7.2 | 100.0 | KEV | Fortra GoAnywhere MFT License Response Servlet Command Injection |
| CVE-2025-53770 | 9.8 | 100.0 | KEV | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2023-29300 | 9.8 | 100.0 | KEV | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
| CVE-2025-59287 | 9.8 | 100.0 | KEV | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
| CVE-2022-41082 | 8.0 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-47986 | 9.8 | 100.0 | KEV | IBM Aspera Faspex code execution |
| CVE-2018-2628 | 9.8 | 100.0 | KEV | Oracle WebLogic Server |
| CVE-2020-10189 | 9.8 | 100.0 | KEV | Zoho ManageEngine |
| CVE-2025-24813 | 10.0 | 100.0 | KEV | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruptio… |
| CVE-2022-35405 | 9.8 | 100.0 | KEV | Zoho ManageEngine |
| CVE-2020-7961 | 9.8 | 100.0 | KEV | Liferay Liferay Portal |
| CVE-2023-46604 | 10.0 | 100.0 | KEV | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization caus… |
| CVE-2025-55182 | 10.0 | 100.0 | KEV | Meta React Server Components |
| CVE-2025-10035 | 9.8 | 100.0 | KEV | Deserialization Vulnerability in GoAnywhere MFT's License Servlet |
| CVE-2019-18935 | 9.8 | 100.0 | KEV | Progress Telerik UI for ASP.NET AJAX |
| CVE-2017-1000353 | 9.8 | 100.0 | KEV | Jenkins Jenkins |
| CVE-2017-9805 | 8.1 | 99.9 | KEV | Apache Struts |
| CVE-2020-0618 | 8.8 | 99.9 | KEV | Microsoft SQL Server |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 71 |
| nvidia | 55 |
| apache | 41 |
| picklescan | 36 |
| ibm | 25 |
| oracle | 16 |
| spring | 14 |
| elated-themes | 11 |
| red hat | 9 |
| crm perks | 8 |
| jenkins project | 8 |
| mikado-themes | 8 |
| adobe | 7 |
| cisco | 7 |
| themerex | 7 |