Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-78 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 667 | 652 | 9 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇██
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 4 · 2026-05 103 · 2026-06 170 · 2026-07 183 · 2026-08 189
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-10520 | 10.0 | 100.0 | KEV | Ivanti Sentry |
| CVE-2019-15107 | 9.8 | 100.0 | KEV | Webmin Webmin |
| CVE-2024-9474 | 6.9 | 99.9 | KEV | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface |
| CVE-2024-51378 | 9.8 | 99.9 | KEV | CyberPersons CyberPanel |
| CVE-2018-11138 | 9.8 | 99.8 | KEV | Quest KACE System Management Appliance |
| CVE-2026-25089 | 9.8 | 99.4 | KEV | Fortinet FortiSandbox |
| CVE-2017-6884 | 8.8 | 98.4 | KEV | Zyxel EMG2926 Routers |
| CVE-2018-19949 | 9.8 | 97.7 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2026-16812 | 10.0 | 56.4 | KEV | VeloCloud Orchestrator OS Command Injection |
| CVE-2025-34037 | 10.0 | 99.8 | — | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series |
| CVE-2025-25256 | 9.8 | 99.1 | — | — |
| CVE-2026-4631 | 9.8 | 96.5 | — | Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argumen… |
| CVE-2026-4480 | 9.0 | 96.2 | — | Samba: samba: remote code execution in printing subsystem via unescaped job description |
| CVE-2026-10727 | 7.2 | 96.2 | — | — |
| CVE-2026-15733 | 9.8 | 96.1 | — | WGDashboard Remote Code Execution vulnerability |
| CVE-2026-9514 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection |
| CVE-2026-9515 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection |
| CVE-2026-9531 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection |
| CVE-2026-9532 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection |
| CVE-2026-9533 | 2.1 | 95.5 | — | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection |