boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-77

Weakness type CWE-77 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
3333155

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▆▅█

2025-09 1 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 3 · 2026-02 6 · 2026-03 0 · 2026-04 4 · 2026-05 93 · 2026-06 61 · 2026-07 59 · 2026-08 89

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-218879.1100.0KEVIvanti Connect Secure and Policy Secure
CVE-2025-100359.899.9KEVDeserialization Vulnerability in GoAnywhere MFT's License Servlet
CVE-2026-80379.899.9KEVOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Co…
CVE-2024-559569.899.8KEVCleo Multiple Products
CVE-2018-199499.897.7KEVQNAP Network Attached Storage (NAS)
CVE-2026-208417.895.7Windows Notepad App Remote Code Execution Vulnerability
CVE-2026-95142.195.5Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
CVE-2026-95152.195.5Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
CVE-2026-95312.195.5Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
CVE-2026-95322.195.5Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
CVE-2026-95332.195.5Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
CVE-2026-95342.195.5Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
CVE-2024-382277.294.4Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-606895.494.4
CVE-2026-428247.594.1M365 Copilot Information Disclosure Vulnerability
CVE-2026-463688.793.3luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
CVE-2026-306239.892.7
CVE-2026-528069.992.2Gogs: RCE via git rebase --exec argument injection in pull request merge
CVE-2026-100602.191.6TRENDnet TEW-432BRP formSetRoute command injection
CVE-2026-100612.191.6TRENDnet TEW-432BRP formWPS command injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft42
totolink34
edimax29
gl.inet21
trendnet10
shibby9
h3c6
d-link5
dokploy5
renovatebot5
comfast4
gl-inet4
wavlink4
roundcube3
ruby3