Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-502 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 471 | 444 | 20 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▆▄
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 2 · 2026-01 2 · 2026-02 4 · 2026-03 7 · 2026-04 7 · 2026-05 27 · 2026-06 183 · 2026-07 125 · 2026-08 89
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | KEV | Apache Log4j2 |
| CVE-2023-0669 | 7.2 | 100.0 | KEV | Fortra GoAnywhere MFT License Response Servlet Command Injection |
| CVE-2025-53770 | 9.8 | 100.0 | KEV | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2025-55182 | 10.0 | 99.9 | KEV | Meta React Server Components |
| CVE-2025-10035 | 9.8 | 99.9 | KEV | Deserialization Vulnerability in GoAnywhere MFT's License Servlet |
| CVE-2020-0618 | 8.8 | 99.9 | KEV | Microsoft SQL Server |
| CVE-2021-26857 | 7.8 | 99.8 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2017-12149 | 9.8 | 99.8 | KEV | Red Hat JBoss Application Server |
| CVE-2025-26399 | 9.8 | 99.8 | KEV | SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnera… |
| CVE-2026-50522 | 9.8 | 99.5 | KEV | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2023-21529 | 8.8 | 99.1 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-58644 | 9.8 | 98.7 | KEV | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-20963 | 9.8 | 98.1 | KEV | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-20131 | 10.0 | 98.1 | KEV | Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability |
| CVE-2026-12569 | 9.3 | 98.1 | KEV | Remote Code Execution (RCE) vulnerability in Windchill PDMlink |
| CVE-2026-45247 | 9.3 | 97.9 | KEV | Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection |
| CVE-2025-23006 | 9.8 | 97.6 | KEV | SonicWall SMA1000 Appliances |
| CVE-2025-42999 | 9.1 | 95.9 | KEV | Insecure Deserialization in SAP NetWeaver (Visual Composer development server) |
| CVE-2026-63077 | 9.8 | 95.5 | KEV | JetBrains TeamCity |
| CVE-2026-45659 | 8.8 | 95.2 | KEV | Microsoft SharePoint Remote Code Execution Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 61 |
| picklescan | 36 |
| apache | 31 |
| nvidia | 21 |
| elated-themes | 11 |
| ibm | 10 |
| oracle | 10 |
| crm perks | 8 |
| mikado-themes | 8 |
| edge-themes | 6 |
| red hat | 6 |
| select-themes | 6 |
| spring | 6 |
| themerex | 6 |
| ancorathemes | 5 |