Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-918
Weakness type CWE-918 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1249 | 1220 | 24 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▆██▂
2025-11 0 · 2025-12 2 · 2026-01 3 · 2026-02 3 · 2026-03 7 · 2026-04 12 · 2026-05 71 · 2026-06 151 · 2026-07 243 · 2026-08 348 · 2026-09 355 · 2026-10 27
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-21985 | 9.8 | 100.0 | KEV | VMware vCenter Server |
| CVE-2021-34473 | 9.1 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-40438 | 9.0 | 100.0 | KEV | mod_proxy SSRF |
| CVE-2024-21893 | 8.2 | 100.0 | KEV | Ivanti Connect Secure, Policy Secure, and Neurons |
| CVE-2021-26855 | 9.1 | 100.0 | KEV | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-41040 | 8.8 | 100.0 | KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-22986 | 9.8 | 100.0 | KEV | F5 BIG-IP and BIG-IQ Centralized Management |
| CVE-2021-22054 | 7.5 | 100.0 | KEV | Omnissa Workspace One UEM |
| CVE-2021-21311 | 7.2 | 99.9 | KEV | SSRF in adminer |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2023-41763 | 5.3 | 99.8 | KEV | Skype for Business Elevation of Privilege Vulnerability |
| CVE-2026-20230 | 8.6 | 99.8 | KEV | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability |
| CVE-2021-21973 | 5.3 | 99.8 | KEV | VMware vCenter Server and Cloud Foundation |
| CVE-2020-7796 | 9.8 | 99.7 | KEV | Synacor Zimbra Collaboration Suite |
| CVE-2019-9621 | 7.5 | 99.6 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2021-21975 | 7.5 | 99.6 | KEV | VMware vRealize Operations Manager API |
| CVE-2016-3718 | 5.5 | 99.5 | KEV | ImageMagick ImageMagick |
| CVE-2021-22175 | 9.8 | 99.0 | KEV | GitLab GitLab |
| CVE-2021-39935 | 6.8 | 98.4 | KEV | GitLab Community and Enterprise Editions |
| CVE-2021-27103 | 9.8 | 95.9 | KEV | Accellion FTA |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 47 |
| ibm | 37 |
| red hat | 28 |
| apache | 25 |
| budibase | 18 |
| openclaw | 18 |
| adobe | 17 |
| mervinpraison | 12 |
| open-webui | 12 |
| 1panel-dev | 9 |
| gitea | 9 |
| nvidia | 8 |
| wwbn | 8 |
| yeswiki | 8 |
| baptistearno | 7 |