Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-94
Weakness type CWE-94 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 1086 | 997 | 71 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅▇█▁
2025-11 1 · 2025-12 1 · 2026-01 6 · 2026-02 8 · 2026-03 11 · 2026-04 7 · 2026-05 76 · 2026-06 146 · 2026-07 178 · 2026-08 261 · 2026-09 289 · 2026-10 15
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2015-1635 | 9.8 | 100.0 | KEV | Microsoft HTTP.sys |
| CVE-2017-9841 | 9.8 | 100.0 | KEV | PHPUnit PHPUnit |
| CVE-2022-22954 | 9.8 | 100.0 | KEV | VMware Workspace ONE Access and Identity Manager |
| CVE-2025-49704 | 8.8 | 100.0 | KEV | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2021-22204 | 6.8 | 100.0 | KEV | Perl Exiftool |
| CVE-2012-0158 | 8.8 | 100.0 | KEV | Microsoft MSCOMCTL.OCX |
| CVE-2022-22963 | 9.8 | 100.0 | KEV | VMware Tanzu Spring Cloud |
| CVE-2022-24816 | 10.0 | 100.0 | KEV | Improper Control of Generation of Code in jai-ext |
| CVE-2025-32432 | 10.0 | 100.0 | KEV | Craft CMS Allows Remote Code Execution |
| CVE-2023-3519 | 9.8 | 100.0 | KEV | Citrix NetScaler ADC and NetScaler Gateway |
| CVE-2021-22205 | 10.0 | 100.0 | KEV | GitLab Community and Enterprise Editions |
| CVE-2019-16759 | 9.8 | 100.0 | KEV | vBulletin vBulletin |
| CVE-2022-22965 | 9.8 | 99.9 | KEV | VMware Spring Framework |
| CVE-2024-23692 | 9.8 | 99.9 | KEV | Rejetto HTTP File Server 2.3m Unauthenticated RCE |
| CVE-2017-7494 | 9.8 | 99.9 | KEV | Samba Samba |
| CVE-2014-6287 | 9.8 | 99.9 | KEV | Rejetto HTTP File Server (HFS) |
| CVE-2018-7602 | 9.8 | 99.9 | KEV | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 |
| CVE-2021-44529 | 9.8 | 99.9 | KEV | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) |
| CVE-2022-3236 | 9.8 | 99.9 | KEV | Sophos Firewall |
| CVE-2026-1281 | 9.8 | 99.9 | KEV | Ivanti Endpoint Manager Mobile (EPMM) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| sourcecodester | 49 |
| ibm | 38 |
| microsoft | 36 |
| code-projects | 28 |
| apache | 14 |
| orval-labs | 14 |
| 13 | |
| flowiseai | 11 |
| vim | 11 |
| itsourcecode | 10 |
| red hat | 10 |
| adobe | 9 |
| craftcms | 8 |
| getgrav | 8 |
| mervinpraison | 8 |