boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-78

Weakness type CWE-78 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
6676529

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇██

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 4 · 2026-05 103 · 2026-06 170 · 2026-07 183 · 2026-08 189

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-1052010.0100.0KEVIvanti Sentry
CVE-2019-151079.8100.0KEVWebmin Webmin
CVE-2024-94746.999.9KEVPAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
CVE-2024-513789.899.9KEVCyberPersons CyberPanel
CVE-2018-111389.899.8KEVQuest KACE System Management Appliance
CVE-2026-250899.899.4KEVFortinet FortiSandbox
CVE-2017-68848.898.4KEVZyxel EMG2926 Routers
CVE-2018-199499.897.7KEVQNAP Network Attached Storage (NAS)
CVE-2026-1681210.056.4KEVVeloCloud Orchestrator OS Command Injection
CVE-2025-3403710.099.8Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
CVE-2025-252569.899.1
CVE-2026-46319.896.5Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argumen…
CVE-2026-44809.096.2Samba: samba: remote code execution in printing subsystem via unescaped job description
CVE-2026-107277.296.2
CVE-2026-157339.896.1WGDashboard Remote Code Execution vulnerability
CVE-2026-95142.195.5Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
CVE-2026-95152.195.5Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
CVE-2026-95312.195.5Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
CVE-2026-95322.195.5Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
CVE-2026-95332.195.5Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
totolink34
dokploy29
ibm26
coollabsio23
dell20
d-link15
red hat15
guardian12
waterfall12
msi11
tp-link systems10
rapid79
shibby9
tenable8
edimax6