Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-77 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 333 | 315 | 5 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▆▅█
2025-09 1 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 3 · 2026-02 6 · 2026-03 0 · 2026-04 4 · 2026-05 93 · 2026-06 61 · 2026-07 59 · 2026-08 89
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21887 | 9.1 | 100.0 | KEV | Ivanti Connect Secure and Policy Secure |
| CVE-2025-10035 | 9.8 | 99.9 | KEV | Deserialization Vulnerability in GoAnywhere MFT's License Servlet |
| CVE-2026-8037 | 9.8 | 99.9 | KEV | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Co… |
| CVE-2024-55956 | 9.8 | 99.8 | KEV | Cleo Multiple Products |
| CVE-2018-19949 | 9.8 | 97.7 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2026-20841 | 7.8 | 95.7 | — | Windows Notepad App Remote Code Execution Vulnerability |
| CVE-2026-9514 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection |
| CVE-2026-9515 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection |
| CVE-2026-9531 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection |
| CVE-2026-9532 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection |
| CVE-2026-9533 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection |
| CVE-2026-9534 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection |
| CVE-2024-38227 | 7.2 | 94.4 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2025-60689 | 5.4 | 94.4 | — | — |
| CVE-2026-42824 | 7.5 | 94.1 | — | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-46368 | 8.7 | 93.3 | — | luci-app-https-dns-proxy Authenticated Command Injection via setInitAction |
| CVE-2026-30623 | 9.8 | 92.7 | — | — |
| CVE-2026-52806 | 9.9 | 92.2 | — | Gogs: RCE via git rebase --exec argument injection in pull request merge |
| CVE-2026-10060 | 2.1 | 91.6 | — | TRENDnet TEW-432BRP formSetRoute command injection |
| CVE-2026-10061 | 2.1 | 91.6 | — | TRENDnet TEW-432BRP formWPS command injection |