boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-917

Weakness type CWE-917 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
22166

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃▂█▃▁▃▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 2 · 2026-05 1 · 2026-06 6 · 2026-07 2 · 2026-08 0 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-260849.8100.0KEVAtlassian Confluence Server and Data Center
CVE-2022-261349.8100.0KEVAtlassian Confluence Server/Data Center
CVE-2021-450469.0100.0KEVApache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a…
CVE-2020-101998.899.9KEVSonatype Nexus Repository
CVE-2020-175309.899.9KEVApache Struts
CVE-2010-18718.899.7KEVRed Hat JBoss Seam 2
CVE-2026-404789.067.2—Improper neutralization of specific syntax patterns for unauthorized expressions in Thy…
CVE-2026-404779.059.7—Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-524399.859.1——
CVE-2026-339388.156.5—Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVE-2026-442097.552.9—Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-655918.951.3—n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
CVE-2026-88887.546.9—CVE-2026-8888
CVE-2026-247378.146.8—jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Exec…
CVE-2026-115619.836.8—SSTI in Soagen Informatics' Apinizer
CVE-2026-911457.134.3—Activiti through 7.1.0.M6 Expression Injection via Mail Task
CVE-2026-417178.134.2—Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
CVE-2026-417298.132.0—Spring Data REST SpEL Injection via Map Key in JSON Patch
CVE-2026-347148.619.6——
CVE-2026-409856.419.4—Data Binding Vulnerability in Spring Web Flow with Unified EL Parser

Most-affected vendors