Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-94 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 594 | 572 | 11 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇█▇
2025-09 1 · 2025-10 1 · 2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 7 · 2026-03 3 · 2026-04 6 · 2026-05 76 · 2026-06 146 · 2026-07 178 · 2026-08 154
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-3519 | 9.8 | 100.0 | KEV | Citrix NetScaler ADC and NetScaler Gateway |
| CVE-2021-22205 | 10.0 | 100.0 | KEV | GitLab Community and Enterprise Editions |
| CVE-2024-23692 | 9.8 | 99.9 | KEV | Rejetto HTTP File Server 2.3m Unauthenticated RCE |
| CVE-2018-7602 | 9.8 | 99.9 | KEV | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 |
| CVE-2021-44529 | 9.8 | 99.9 | KEV | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) |
| CVE-2026-34197 | 8.8 | 99.9 | KEV | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could… |
| CVE-2026-15410 | 7.2 | 99.5 | KEV | SonicWall SMA1000 Appliances |
| CVE-2024-21351 | 7.6 | 98.1 | KEV | Windows SmartScreen Security Feature Bypass Vulnerability |
| CVE-2024-20359 | 6.0 | 97.1 | KEV | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| CVE-2026-9198 | 9.8 | 96.9 | KEV | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation |
| CVE-2025-62593 | 9.4 | 60.5 | KEV | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack |
| CVE-2026-6875 | 9.5 | 97.9 | — | Sandbox Escape in ServiceNow AI Platform |
| CVE-2024-21378 | 8.8 | 95.5 | — | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-27577 | 9.4 | 94.6 | — | n8n: Expression Sandbox Escape Leads to RCE |
| CVE-2026-58138 | 9.3 | 93.8 | — | Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators |
| CVE-2026-50741 | 8.8 | 90.7 | — | — |
| CVE-2026-47668 | 10.0 | 90.4 | — | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner |
| CVE-2026-46442 | 9.4 | 88.2 | — | Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbo… |
| CVE-2026-59865 | 9.3 | 87.1 | — | Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot… |
| CVE-2026-4800 | 8.1 | 83.9 | — | lodash vulnerable to Code Injection via `_.template` imports key names |
| Vendor | CVEs |
|---|---|
| sourcecodester | 31 |
| microsoft | 26 |
| ibm | 25 |
| code-projects | 17 |
| flowiseai | 11 |
| 11 | |
| vim | 11 |
| apache | 8 |
| itsourcecode | 8 |
| orval-labs | 8 |
| getgrav | 7 |
| koxudaxi | 7 |
| mervinpraison | 6 |
| sonicwall | 6 |
| gitlab | 5 |