boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-611

Weakness type CWE-611 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1151048

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▄▅█▁

2025-11 1 · 2025-12 2 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 4 · 2026-05 6 · 2026-06 15 · 2026-07 16 · 2026-08 20 · 2026-09 40 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-341029.8100.0KEVXXE can expose crypt key and other secrets granting full admin access
CVE-2019-96709.8100.0KEVSynacor Zimbra Collaboration Suite (ZCS)
CVE-2025-27769.399.2KEVSysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
CVE-2025-583608.299.1KEVGeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WM…
CVE-2025-27759.398.7KEVSysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
CVE-2019-136087.598.2KEVCitrix StoreFront Server
CVE-2016-95636.597.8KEVSAP NetWeaver
CVE-2023-457277.588.9KEVNorth Grid Proself
CVE-2025-684938.198.8—Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
CVE-2026-261717.582.4—.NET Denial of Service Vulnerability
CVE-2026-483599.661.7—Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE'…
CVE-2026-406829.156.5—Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
CVE-2026-479607.456.3—ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVE-2026-498759.855.3—Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointRe…
CVE-2023-353896.553.5—Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-892608.752.8—MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callba…
CVE-2026-220167.551.6——
CVE-2026-568178.351.3—Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and en…
CVE-2026-654327.549.4—Apache CXF: XXE via WSDL/XSD import parsing
CVE-2026-100259.849.2—IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability

Most-affected vendors