Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-93
Weakness type CWE-93 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 101 | 99 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▄▇▅██▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 14 · 2026-08 26 · 2026-09 26 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2026-72590 | 9.8 | 80.5 | — | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter |
| CVE-2026-82854 | 9.3 | 79.8 | — | Nodemailer before 8.0.3 SMTP Command Injection via envelope.size |
| CVE-2026-15429 | 5.1 | 71.4 | — | Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v |
| CVE-2026-42258 | 5.8 | 68.4 | — | net-imap: Command Injection via unvalidated Symbol inputs |
| CVE-2026-42578 | 2.9 | 65.9 | — | Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| CVE-2026-12357 | 7.2 | 64.2 | — | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution V… |
| CVE-2026-82853 | 6.9 | 62.5 | — | Nodemailer before 8.0.5 SMTP Command Injection via CRLF |
| CVE-2026-57281 | 7.5 | 59.0 | — | — |
| CVE-2026-47240 | 5.8 | 56.1 | — | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
| CVE-2026-77550 | 10.0 | 55.1 | — | — |
| CVE-2026-75484 | 6.9 | 53.3 | — | HTTP/2 header field values containing CR, LF or NUL are passed to the application unval… |
| CVE-2026-84372 | 9.8 | 52.5 | — | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined c… |
| CVE-2026-50629 | 5.3 | 51.6 | — | Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier |
| CVE-2026-44092 | 8.8 | 50.8 | — | Missing input validation / stripping of CRLF characters in SystemConfigManager |
| CVE-2026-75925 | 9.4 | 50.3 | — | IXON VPN Client CRLF Injection |
| CVE-2026-12143 | 8.7 | 50.2 | — | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje… |
| CVE-2026-90819 | 6.9 | 49.9 | — | a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java B… |
| CVE-2026-45067 | 6.3 | 46.8 | — | Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address |
| CVE-2026-12127 | 5.3 | 46.6 | — | WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email … |