Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-89
Weakness type CWE-89 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 2045 | 2001 | 31 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇▇▇█▂
2025-11 0 · 2025-12 4 · 2026-01 3 · 2026-02 5 · 2026-03 11 · 2026-04 6 · 2026-05 203 · 2026-06 401 · 2026-07 389 · 2026-08 446 · 2026-09 494 · 2026-10 43
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-29824 | 9.6 | 100.0 | KEV | Ivanti Endpoint Manager (EPM) |
| CVE-2023-34362 | 9.8 | 100.0 | KEV | Progress MOVEit Transfer |
| CVE-2019-7481 | 7.5 | 100.0 | KEV | SonicWall SMA100 |
| CVE-2025-25257 | 9.6 | 100.0 | KEV | Fortinet FortiWeb |
| CVE-2024-9465 | 9.2 | 99.9 | KEV | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure |
| CVE-2023-48788 | 9.3 | 99.9 | KEV | Fortinet FortiClient EMS |
| CVE-2019-12989 | 9.8 | 99.9 | KEV | Citrix SD-WAN and NetScaler |
| CVE-2026-21643 | 9.1 | 99.8 | KEV | Fortinet FortiClient EMS |
| CVE-2024-6670 | 9.8 | 99.8 | KEV | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability |
| CVE-2020-17463 | 9.8 | 99.8 | KEV | Fuel CMS Fuel CMS |
| CVE-2017-18362 | 9.8 | 99.7 | KEV | Kaseya Virtual System/Server Administrator (VSA) |
| CVE-2025-57819 | 10.0 | 99.7 | KEV | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE |
| CVE-2020-5722 | 9.8 | 99.7 | KEV | Grandstream UCM6200 |
| CVE-2024-43468 | 9.8 | 99.6 | KEV | Microsoft Configuration Manager Remote Code Execution Vulnerability |
| CVE-2021-42258 | 9.8 | 99.5 | KEV | BQE BillQuick Web Suite |
| CVE-2018-7841 | 9.8 | 99.4 | KEV | Schneider Electric U.motion Builder |
| CVE-2016-2386 | 9.8 | 99.4 | KEV | SAP NetWeaver |
| CVE-2021-44026 | 9.8 | 99.4 | KEV | Roundcube Roundcube Webmail |
| CVE-2025-25181 | 5.8 | 99.0 | KEV | Advantive VeraCore |
| CVE-2024-9379 | 7.2 | 98.7 | KEV | Ivanti Cloud Services Appliance (CSA) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| itsourcecode | 142 |
| sourcecodester | 123 |
| code-projects | 80 |
| codeastro | 41 |
| helmholz | 40 |
| mb connect line | 40 |
| ibm | 27 |
| apache | 17 |
| open ises | 17 |
| dell | 15 |
| microsoft | 15 |
| mathurvishal | 14 |
| cisco | 13 |
| oracle | 13 |
| koha community | 12 |