Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-88
Weakness type CWE-88 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 131 | 127 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▆█▁
2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 3 · 2026-05 9 · 2026-06 17 · 2026-07 19 · 2026-08 29 · 2026-09 44 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2016-10033 | 9.8 | 100.0 | KEV | PHP PHPMailer |
| CVE-2022-36804 | 8.8 | 99.9 | KEV | Atlassian Bitbucket Server and Data Center |
| CVE-2026-24061 | 9.8 | 99.9 | KEV | GNU InetUtils |
| CVE-2024-41710 | 6.8 | 98.6 | KEV | Mitel SIP Phones |
| CVE-2026-86060 | 9.2 | 93.5 | KEV | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| CVE-2026-40047 | 9.1 | 83.7 | — | Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar… |
| CVE-2026-61459 | 9.3 | 83.2 | — | MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools |
| CVE-2026-40079 | 8.6 | 76.3 | — | Cacti: Command Injection via escape_command() no-op in RRDtool execution |
| CVE-2026-54501 | 9.4 | 67.6 | — | Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git UR… |
| CVE-2026-65770 | 10.0 | 63.2 | — | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
| CVE-2026-47114 | 8.6 | 63.1 | — | IINA < 1.4.3 Command Execution via iina://open URL Scheme |
| CVE-2026-73240 | 9.8 | 62.9 | — | Apache Allura: Git command injection |
| CVE-2026-72538 | 8.8 | 60.8 | — | PrefectHQ Prefect - Argument Injection |
| CVE-2026-44189 | 7.8 | 60.0 | — | Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code exe… |
| CVE-2026-57572 | 10.0 | 59.6 | — | Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.… |
| CVE-2026-76220 | 8.7 | 58.6 | — | GitPython before 3.1.58 Command Execution via split_single_char_options |
| CVE-2026-40938 | 8.5 | 58.4 | — | Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Inje… |
| CVE-2026-44449 | 9.1 | 57.0 | — | Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape |
| CVE-2026-42266 | 8.8 | 56.8 | — | JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali… |
| CVE-2026-76218 | 7.7 | 55.9 | — | GitPython before 3.1.58 Remote Code Execution via Repo.init |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 9 |
| gitpython-developers | 8 |
| aws | 5 |
| apache | 3 |
| pgadmin.org | 3 |
| cloudfoundry foundation | 2 |
| dell | 2 |
| flux159 | 2 |
| jupyterlab | 2 |
| netcore | 2 |
| nfriedly | 2 |
| nm-l2tp | 2 |
| openclaw | 2 |
| paessler | 2 |
| prefecthq | 2 |