Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-80 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 45 | 42 | 2 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▆▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 17 · 2026-07 11 · 2026-08 8
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-19953 | 6.1 | 97.6 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2018-19943 | 5.4 | 96.9 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2026-50229 | 6.1 | 90.2 | — | Apache Tomcat: XSS in number guess example |
| CVE-2026-75872 | 6.9 | 50.7 | — | HTML Injection in MailerUp double opt-in verification email |
| CVE-2025-62198 | 5.4 | 41.1 | — | Apache Atlas: Stored XSS in Create Entity page |
| CVE-2026-52816 | 5.4 | 39.2 | — | Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs le… |
| CVE-2026-52854 | 8.6 | 36.2 | — | mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser fun… |
| CVE-2026-73237 | 6.1 | 36.0 | — | Apache Allura: XSS in markdown pipeline |
| CVE-2026-73238 | 6.1 | 36.0 | — | Apache Allura: XSS in code display |
| CVE-2026-41611 | 7.8 | 35.3 | — | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-34033 | 5.4 | 30.5 | — | Apache Answer: HTML Content Injection in Email |
| CVE-2026-48910 | 6.5 | 28.0 | — | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing |
| CVE-2026-13225 | 5.3 | 27.6 | — | Stored XSS in ticket confirmation page |
| CVE-2026-75082 | 2.1 | 26.1 | — | Webkul Bagisto Customer-Registration Notification Email register cross site scripting |
| CVE-2026-12812 | 2.0 | 26.1 | — | Radware Cyber Controller HTML Report Generation HTML injection |
| CVE-2026-57532 | 8.8 | 26.0 | — | — |
| CVE-2026-57534 | 2.1 | 26.0 | — | Stored XSS in pretix-pages |
| CVE-2026-13314 | 2.0 | 26.0 | — | Stored XSS in pretix-digital |
| CVE-2026-57535 | 2.1 | 23.5 | — | — |
| CVE-2025-8029 | 8.1 | 23.3 | — | javascript: URLs executed on object and embed tags |
| Vendor | CVEs |
|---|---|
| apache | 6 |
| pretix | 6 |
| calcom | 2 |
| qnap systems | 2 |
| alaev | 1 |
| anglesharp | 1 |
| armiya information technologies ltd. co | 1 |
| backdropcms | 1 |
| bolt | 1 |
| chocobozzz | 1 |
| cisco | 1 |
| commenthol | 1 |
| datacycle-engine | 1 |
| flowise | 1 |
| fortinet | 1 |