boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-94

Weakness type CWE-94 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
59457211

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇█▇

2025-09 1 · 2025-10 1 · 2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 7 · 2026-03 3 · 2026-04 6 · 2026-05 76 · 2026-06 146 · 2026-07 178 · 2026-08 154

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-35199.8100.0KEVCitrix NetScaler ADC and NetScaler Gateway
CVE-2021-2220510.0100.0KEVGitLab Community and Enterprise Editions
CVE-2024-236929.899.9KEVRejetto HTTP File Server 2.3m Unauthenticated RCE
CVE-2018-76029.899.9KEVDrupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
CVE-2021-445299.899.9KEVIvanti Endpoint Manager Cloud Service Appliance (EPM CSA)
CVE-2026-341978.899.9KEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could…
CVE-2026-154107.299.5KEVSonicWall SMA1000 Appliances
CVE-2024-213517.698.1KEVWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2024-203596.097.1KEVCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2026-91989.896.9KEVUnauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
CVE-2025-625939.460.5KEVRay is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
CVE-2026-68759.597.9Sandbox Escape in ServiceNow AI Platform
CVE-2024-213788.895.5Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-275779.494.6n8n: Expression Sandbox Escape Leads to RCE
CVE-2026-581389.393.8Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVE-2026-507418.890.7
CVE-2026-4766810.090.4DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVE-2026-464429.488.2Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbo…
CVE-2026-598659.387.1Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiot…
CVE-2026-48008.183.9lodash vulnerable to Code Injection via `_.template` imports key names

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
sourcecodester31
microsoft26
ibm25
code-projects17
flowiseai11
google11
vim11
apache8
itsourcecode8
orval-labs8
getgrav7
koxudaxi7
mervinpraison6
sonicwall6
gitlab5