Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-78
Weakness type CWE-78 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1279 | 1152 | 111 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▅▇█▁
2025-11 4 · 2025-12 10 · 2026-01 3 · 2026-02 6 · 2026-03 9 · 2026-04 8 · 2026-05 104 · 2026-06 170 · 2026-07 183 · 2026-08 310 · 2026-09 343 · 2026-10 16
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2014-6271 | 9.8 | 100.0 | KEV | GNU Bourne-Again Shell (Bash) |
| CVE-2021-1498 | 9.8 | 100.0 | KEV | Cisco HyperFlex HX Command Injection Vulnerabilities |
| CVE-2019-16920 | 9.8 | 100.0 | KEV | D-Link Multiple Routers |
| CVE-2022-44877 | 9.8 | 100.0 | KEV | CWP Control Web Panel |
| CVE-2020-8515 | 9.8 | 100.0 | KEV | DrayTek Multiple Vigor Routers |
| CVE-2020-9054 | 9.8 | 100.0 | KEV | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-auth… |
| CVE-2024-4577 | 9.8 | 100.0 | KEV | Argument Injection in PHP-CGI |
| CVE-2020-25506 | 9.8 | 100.0 | KEV | D-Link DNS-320 Device |
| CVE-2019-10149 | 9.0 | 100.0 | KEV | Exim Mail Transfer Agent (MTA) |
| CVE-2018-10562 | 9.8 | 100.0 | KEV | Dasan Gigabit Passive Optical Network (GPON) Routers |
| CVE-2022-30525 | 9.8 | 100.0 | KEV | Zyxel Multiple Firewalls |
| CVE-2014-7169 | 9.8 | 100.0 | KEV | GNU Bourne-Again Shell (Bash) |
| CVE-2021-1497 | 9.8 | 100.0 | KEV | Cisco HyperFlex HX Command Injection Vulnerabilities |
| CVE-2026-10520 | 10.0 | 100.0 | KEV | Ivanti Sentry |
| CVE-2024-45519 | 10.0 | 100.0 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2021-36260 | 9.8 | 100.0 | KEV | Hikvision Security cameras web server |
| CVE-2021-35394 | 9.8 | 100.0 | KEV | Realtek Jungle Software Development Kit (SDK) |
| CVE-2019-15107 | 9.8 | 100.0 | KEV | Webmin Webmin |
| CVE-2025-48703 | 9.0 | 99.9 | KEV | CWP Control Web Panel |
| CVE-2014-6278 | 8.8 | 99.9 | KEV | GNU GNU Bash |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 79 |
| dell | 38 |
| totolink | 36 |
| red hat | 31 |
| d-link | 30 |
| dokploy | 30 |
| draytek | 26 |
| coollabsio | 24 |
| phoenix contact | 20 |
| tp-link systems | 19 |
| carlo gavazzi automation | 14 |
| pepperl+fuchs | 14 |
| geovision | 13 |
| guardian | 12 |
| hewlett packard enterprise (hpe) | 12 |