boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-918

Weakness type CWE-918 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
7076919

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▇

2025-09 0 · 2025-10 2 · 2025-11 0 · 2025-12 2 · 2026-01 2 · 2026-02 3 · 2026-03 4 · 2026-04 12 · 2026-05 67 · 2026-06 152 · 2026-07 243 · 2026-08 208

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-219859.8100.0KEVVMware vCenter Server
CVE-2021-268559.1100.0KEVMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-344739.1100.0KEVMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-404389.0100.0KEVmod_proxy SSRF
CVE-2024-218938.2100.0KEVIvanti Connect Secure, Policy Secure, and Neurons
CVE-2025-618847.599.9KEVOracle E-Business Suite
CVE-2026-202308.699.7KEVCisco Unified Communications Manager Server-Side Request Forgery Vulnerability
CVE-2021-219757.599.5KEVVMware vRealize Operations Manager API
CVE-2026-1540910.099.4KEVSonicWall SMA1000 Appliances
CVE-2026-445788.698.5Next.js: Server-side request forgery in applications using WebSocket upgrades
CVE-2026-455025.097.3Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-712585.396.9BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
CVE-2025-712595.396.0BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS
CVE-2026-483327.795.5ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-93129.293.2Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to…
CVE-2026-1377310.087.9IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used…
CVE-2026-171926.382.2VeloCloud Orchestrator Missing Input Validation SSRF
CVE-2026-598677.178.3Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-401754.877.8Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-541579.076.5LobeHub: Unauthenticated SSRF in `/webapi/proxy`

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft33
red hat23
apache14
ibm14
budibase13
gitea9
open-webui9
nvidia8
openclaw8
1panel-dev7
adobe7
baptistearno7
mervinpraison6
decolua5
netflix5