Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-77
Weakness type CWE-77 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 538 | 491 | 35 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▃▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▃▃▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▃▃▁▁▅▃▅▁▅▁▃▁▁▁▁▅▃▁▆▁▁▃▁▅█▁▆▁▁▃▁▃▁▁▁
2024-09 2 · 2024-10 4 · 2024-11 0 · 2024-12 3 · 2025-01 0 · 2025-02 0 · 2025-03 1 · 2025-04 0 · 2025-05 1 · 2025-06 0 · 2025-07 0 · 2025-08 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-3400 | 10.0 | 100.0 | KEV | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalPr… |
| CVE-2023-1671 | 9.8 | 100.0 | KEV | Sophos Web Appliance |
| CVE-2024-21887 | 9.1 | 100.0 | KEV | Ivanti Connect Secure and Policy Secure |
| CVE-2023-1389 | 8.8 | 100.0 | KEV | TP-Link Archer AX21 |
| CVE-2012-1823 | 9.8 | 100.0 | KEV | PHP PHP |
| CVE-2024-3273 | 7.3 | 100.0 | KEV | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command inje… |
| CVE-2025-10035 | 9.8 | 100.0 | KEV | Deserialization Vulnerability in GoAnywhere MFT's License Servlet |
| CVE-2016-1555 | 9.8 | 99.9 | KEV | NETGEAR Wireless Access Point (WAP) Devices |
| CVE-2023-20887 | 9.8 | 99.9 | KEV | VMware Aria Operations for Networks |
| CVE-2024-12987 | 6.9 | 99.9 | KEV | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection |
| CVE-2007-3010 | 9.8 | 99.9 | KEV | Alcatel OmniPCX Enterprise |
| CVE-2015-2051 | 8.8 | 99.9 | KEV | D-Link DIR-645 Router |
| CVE-2024-55956 | 9.8 | 99.8 | KEV | Cleo Multiple Products |
| CVE-2025-4008 | 8.7 | 99.8 | KEV | Arbitrary Command Injection in Smartbedded MeteoBridge |
| CVE-2026-42271 | 8.7 | 99.8 | KEV | LiteLLM: Authenticated command execution via MCP stdio test endpoints |
| CVE-2025-29635 | 7.2 | 99.8 | KEV | D-Link DIR-823X |
| CVE-2024-12356 | 9.8 | 99.7 | KEV | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA) |
| CVE-2026-8037 | 9.8 | 99.5 | KEV | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Co… |
| CVE-2005-2773 | 9.8 | 99.5 | KEV | Hewlett Packard (HP) OpenView Network Node Manager |
| CVE-2016-20017 | 9.8 | 99.2 | KEV | D-Link DSL-2750B Devices |