Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-918 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 707 | 691 | 9 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▇
2025-09 0 · 2025-10 2 · 2025-11 0 · 2025-12 2 · 2026-01 2 · 2026-02 3 · 2026-03 4 · 2026-04 12 · 2026-05 67 · 2026-06 152 · 2026-07 243 · 2026-08 208
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-21985 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2021-26855 | 9.1 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34473 | 9.1 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-40438 | 9.0 | 100.0 | KEV | mod_proxy SSRF |
| CVE-2024-21893 | 8.2 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and Neurons |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2026-20230 | 8.6 | 99.7 | KEV | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability |
| CVE-2021-21975 | 7.5 | 99.5 | KEV | VMware vRealize Operations Manager API |
| CVE-2026-15409 | 10.0 | 99.4 | KEV | SonicWall SMA1000 Appliances |
| CVE-2026-44578 | 8.6 | 98.5 | — | Next.js: Server-side request forgery in applications using WebSocket upgrades |
| CVE-2026-45502 | 5.0 | 97.3 | — | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2025-71258 | 5.3 | 96.9 | — | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb |
| CVE-2025-71259 | 5.3 | 96.0 | — | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS |
| CVE-2026-48332 | 7.7 | 95.5 | — | ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-9312 | 9.2 | 93.2 | — | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to… |
| CVE-2026-13773 | 10.0 | 87.9 | — | IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used… |
| CVE-2026-17192 | 6.3 | 82.2 | — | VeloCloud Orchestrator Missing Input Validation SSRF |
| CVE-2026-59867 | 7.1 | 78.3 | — | Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref |
| CVE-2026-40175 | 4.8 | 77.8 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-54157 | 9.0 | 76.5 | — | LobeHub: Unauthenticated SSRF in `/webapi/proxy` |
| Vendor | CVEs |
|---|---|
| microsoft | 33 |
| red hat | 23 |
| apache | 14 |
| ibm | 14 |
| budibase | 13 |
| gitea | 9 |
| open-webui | 9 |
| nvidia | 8 |
| openclaw | 8 |
| 1panel-dev | 7 |
| adobe | 7 |
| baptistearno | 7 |
| mervinpraison | 6 |
| decolua | 5 |
| netflix | 5 |