Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-79 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 2237 | 2147 | 6 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▅
2025-09 3 · 2025-10 1 · 2025-11 1 · 2025-12 21 · 2026-01 4 · 2026-02 5 · 2026-03 12 · 2026-04 9 · 2026-05 262 · 2026-06 643 · 2026-07 751 · 2026-08 461
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-3580 | 6.1 | 99.7 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2026-42897 | 8.1 | 99.3 | KEV | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2024-43573 | 6.5 | 98.6 | KEV | Windows MSHTML Platform Spoofing Vulnerability |
| CVE-2018-6882 | 6.1 | 97.8 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2018-19953 | 6.1 | 97.6 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2018-19943 | 5.4 | 96.9 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2023-2164 | 5.4 | 99.2 | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in… |
| CVE-2021-30119 | 5.4 | 98.9 | — | Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6 |
| CVE-2026-20945 | 4.6 | 97.8 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-20959 | 4.6 | 93.8 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47999 | 4.8 | 93.7 | — | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48320 | 8.5 | 91.9 | — | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2020-1106 | 5.4 | 86.6 | — | Microsoft Office SharePoint XSS Vulnerability |
| CVE-2023-36891 | 8.0 | 79.0 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2023-36892 | 8.0 | 79.0 | — | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48294 | 7.4 | 78.1 | — | — |
| CVE-2024-43481 | 6.5 | 77.1 | — | Power BI Report Server Spoofing Vulnerability |
| CVE-2020-1055 | 5.5 | 76.5 | — | Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability |
| CVE-2020-1099 | 5.4 | 74.2 | — | Microsoft Office SharePoint XSS Vulnerability |
| CVE-2020-1100 | 5.4 | 74.2 | — | Microsoft Office SharePoint XSS Vulnerability |
| Vendor | CVEs |
|---|---|
| microsoft | 99 |
| adobe | 78 |
| 30 | |
| sourcecodester | 30 |
| siyuan-note | 23 |
| ibm | 22 |
| frappe | 20 |
| open ises | 18 |
| code-projects | 17 |
| watchguard | 16 |
| drupal | 15 |
| getgrav | 13 |
| joomla! project | 13 |
| oracle | 13 |
| cure53 | 12 |