Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-787 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 791 | 551 | 18 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▁▁▁▁▁▁▁▃█▇▅
2025-09 26 · 2025-10 9 · 2025-11 2 · 2025-12 5 · 2026-01 7 · 2026-02 2 · 2026-03 10 · 2026-04 5 · 2026-05 56 · 2026-06 187 · 2026-07 169 · 2026-08 115
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-22457 | 9.8 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and ZTA Gateways |
| CVE-2025-0282 | 9.0 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and ZTA Gateways |
| CVE-2021-4034 | 7.8 | 99.9 | KEV | Red Hat Polkit |
| CVE-2025-9242 | 9.3 | 99.8 | KEV | WatchGuard Firebox iked Out of Bounds Write Vulnerability |
| CVE-2018-8174 | 7.5 | 99.8 | KEV | Microsoft Windows |
| CVE-2023-27997 | 9.8 | 99.7 | KEV | Fortinet FortiOS and FortiProxy SSL-VPN |
| CVE-2024-21762 | 9.8 | 99.7 | KEV | Fortinet FortiOS |
| CVE-2021-1732 | 7.8 | 99.5 | KEV | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2022-2294 | 8.8 | 99.3 | KEV | WebRTC WebRTC |
| CVE-2022-21882 | 7.8 | 98.9 | KEV | Win32k Elevation of Privilege Vulnerability |
| CVE-2020-1054 | 7.0 | 98.9 | KEV | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-34448 | 6.8 | 98.5 | KEV | Scripting Engine Memory Corruption Vulnerability |
| CVE-2025-14733 | 9.3 | 97.9 | KEV | WatchGuard Firebox iked Out of Bounds Write Vulnerability |
| CVE-2022-41128 | 8.8 | 97.7 | KEV | Windows Scripting Languages Remote Code Execution Vulnerability |
| CVE-2022-41125 | 7.8 | 86.4 | KEV | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
| CVE-2022-41073 | 7.8 | 82.6 | KEV | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-11645 | 8.8 | 81.0 | KEV | Google Chromium V8 |
| CVE-2025-22225 | 8.2 | 60.0 | KEV | VMware ESXi |
| CVE-2026-43500 | 7.8 | 99.8 | — | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present |
| CVE-2021-36952 | 7.8 | 98.9 | — | Visual Studio Remote Code Execution Vulnerability |
| Vendor | CVEs |
|---|---|
| linux | 257 |
| 69 | |
| adobe | 40 |
| microsoft | 29 |
| apple | 28 |
| ibm | 24 |
| red hat | 20 |
| mediatek | 19 |
| zephyrproject | 19 |
| ffmpeg | 10 |
| watchguard | 10 |
| imagemagick | 9 |
| apache | 8 |
| mozilla | 8 |
| qualcomm | 8 |