Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-89 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1309 | 1294 | 8 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅██▆
2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 2 · 2026-01 3 · 2026-02 2 · 2026-03 8 · 2026-04 6 · 2026-05 201 · 2026-06 401 · 2026-07 389 · 2026-08 284
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-7481 | 7.5 | 100.0 | KEV | SonicWall SMA100 |
| CVE-2026-9082 | 9.8 | 99.8 | KEV | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 |
| CVE-2017-18362 | 9.8 | 99.7 | KEV | Kaseya Virtual System/Server Administrator (VSA) |
| CVE-2026-60137 | 5.9 | 99.4 | KEV | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query |
| CVE-2024-43468 | 9.8 | 99.1 | KEV | Microsoft Configuration Manager Remote Code Execution Vulnerability |
| CVE-2021-20016 | 9.8 | 98.4 | KEV | SonicWall SSLVPN SMA100 |
| CVE-2026-72898 | 10.0 | 95.4 | KEV | Metabase SQL injection via password reset endpoint |
| CVE-2020-29574 | 9.8 | 91.1 | KEV | Sophos CyberoamOS |
| CVE-2026-47992 | 7.2 | 97.2 | — | Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('S… |
| CVE-2026-20947 | 8.8 | 97.0 | — | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-48134 | 5.6 | 90.5 | — | SQL injection issue in UserCheck Portal when DLP Software Blade is active |
| CVE-2026-48136 | 4.1 | 89.9 | — | Authenticated Administrator Role-Based Access Control Bypass in Compliance |
| CVE-2026-17191 | 8.5 | 85.5 | — | VeloCloud Orchestrator Flow Metrics API SQL Injection |
| CVE-2026-35152 | 8.8 | 81.8 | — | Apache Fineract: SQL injection in runreports endpoint |
| CVE-2025-34112 | 10.0 | 79.1 | — | Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE |
| CVE-2026-3326 | 8.6 | 77.6 | — | XStore < 9.7.3 - Unauthenticated SQLi |
| CVE-2026-46670 | 9.8 | 74.6 | — | YesWiki: Unauthenticated SQL Injection |
| CVE-2026-8054 | 10.0 | 73.6 | — | Unauthenticated SQL Injection in dotCMS Publish Audit API |
| CVE-2026-11840 | 8.8 | 73.6 | — | SQL Injection |
| CVE-2026-44680 | 7.6 | 71.3 | — | MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys |
| Vendor | CVEs |
|---|---|
| itsourcecode | 79 |
| sourcecodester | 70 |
| code-projects | 56 |
| helmholz | 40 |
| mb connect line | 40 |
| codeastro | 36 |
| open ises | 17 |
| koha community | 12 |
| ibm | 11 |
| apache | 9 |
| dell | 9 |
| 10web | 8 |
| aiopmsd | 8 |
| guardian | 7 |
| microsoft | 7 |