Data as of: 2026-09-13 (refreshed daily from upstream cvelistV5 — pull this page tomorrow and the rankings will have moved).
🌐 中文版:README.cn.md —— same data, Chinese CWE names (MITRE 官方中文翻译, ~91% 覆盖;缺失自动回退英文).
The 10 newest CVEs (descending CVE id = newest published first).
| CVE | Score | Product | CWE | Description |
|---|---|---|---|---|
| CVE-2026-90668 | 8.7 | UnrealIRCd/UnrealIRCd | 770 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the… |
| CVE-2026-90651 | 8.1 | Socket/Socket Firewall | 295 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before… |
| CVE-2026-90648 | 7.1 | WebAssembly/wabt | 252 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some… |
| CVE-2026-90647 | 9.1 | Kalkitech/ASE2000 V2 Communication Test Set | 295 | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows… |
| CVE-2026-90616 | 7.4 | Flatpak/Flatpak | 61 | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read… |
| CVE-2026-90560 | 8.8 | luben/zstd-jni | 125 | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read… |
| CVE-2026-90559 | 8.7 | xerial/snappy-java | 787 | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in… |
| CVE-2026-90558 | 9.8 | irontec/sngrep | 121 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP… |
| CVE-2026-90557 | 6.9 | freeciv/freeciv | 125 | Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read… |
| CVE-2026-90556 | 8.5 | freeciv/freeciv | 122 | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load()… |
Click a CVE id for the full record on NVD.
This page is a living mirror of the upstream CVE index. The tables below (per-year stats, top-10 CWE mistakes, top-10 by severity) are regenerated by the daily CI run, not curated by hand.
117,523 CVEs across 683 distinct CWEs since 2024.
Top 10 CWE by CVE count.
| Rank | CWE | Name | CVEs | Avg score |
|---|---|---|---|---|
| 1 | 79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 17,205 | 6.17 |
| 2 | 89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 7,730 | 7.46 |
| 3 | 862 | Missing Authorization | 6,336 | 5.97 |
| 4 | 74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 4,294 | 7.02 |
| 5 | 22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 3,321 | 7.18 |
| 6 | 352 | Cross-Site Request Forgery (CSRF) | 3,276 | 5.81 |
| 7 | 94 | Improper Control of Generation of Code ('Code Injection') | 2,793 | 6.79 |
| 8 | 416 | Use After Free | 2,570 | 7.67 |
| 9 | 78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 2,532 | 8.10 |
| 10 | 125 | Out-of-bounds Read | 2,320 | 6.34 |
Top 10 CWE by average CVSS score. Min 10 CVEs to suppress single-CWE outliers.
| Rank | CWE | Name | CVEs | Avg score | Max |
|---|---|---|---|---|---|
| 1 | 506 | Embedded Malicious Code | 48 | 9.15 | 10.0 |
| 2 | 95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | 136 | 8.56 | 10.0 |
| 3 | 565 | Reliance on Cookies without Validation and Integrity Checking | 18 | 8.38 | 9.8 |
| 4 | 502 | Deserialization of Untrusted Data | 1,748 | 8.34 | 10.0 |
| 5 | 288 | Authentication Bypass Using an Alternate Path or Channel | 465 | 8.27 | 10.0 |
| 6 | 917 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') | 29 | 8.21 | 10.0 |
| 7 | 29 | Path Traversal: '..filename' | 49 | 8.16 | 9.9 |
| 8 | 120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | 1,118 | 8.12 | 10.0 |
| 9 | 306 | Missing Authentication for Critical Function | 1,273 | 8.12 | 10.0 |
| 10 | 121 | Stack-based Buffer Overflow | 1,835 | 8.12 | 10.0 |
Per-year CVE volume and severity.
| Year | CVEs | Scored | Avg score | Max score |
|---|---|---|---|---|
| 2026 (YTD as of 2026-09-13) | 56,164 | 52,943 | 7.08 | 10.0 |
| 2025 | 43,471 | 42,044 | 6.79 | 10.0 |
| 2024 | 38,451 | 37,057 | 6.81 | 10.0 |
| 2023 | 30,616 | 24,751 | 6.73 | 10.0 |
| 2022 | 26,445 | 17,468 | 6.79 | 10.0 |
| 2021 | 22,601 | 10,834 | 6.83 | 10.0 |
| 2020 | 19,392 | 6,916 | 6.84 | 10.0 |
| 2019 | 16,096 | 3,527 | 6.84 | 10.0 |
| 2018 | 16,188 | 2,292 | 6.92 | 10.0 |
| 2017 | 14,762 | 1,375 | 7.18 | 10.0 |
| 2016 | 9,367 | 408 | 7.10 | 10.0 |
| 2015 | 8,111 | 252 | 6.26 | 10.0 |
| 2014 | 8,427 | 290 | 6.62 | 10.0 |
| 2013 | 6,221 | 154 | 7.44 | 10.0 |
| 2012 | 5,488 | 147 | 7.82 | 10.0 |
| 2011 | 4,646 | 96 | 7.54 | 10.0 |
| 2010 | 5,074 | 95 | 7.74 | 10.0 |
| 2009 | 4,921 | 65 | 8.01 | 10.0 |
| 2008 | 7,005 | 41 | 7.31 | 9.8 |
| 2007 | 6,458 | 38 | 8.00 | 9.8 |
| 2006 | 6,995 | 42 | 7.94 | 9.8 |
| 2005 | 4,627 | 21 | 6.23 | 9.8 |
| 2004 | 2,644 | 11 | 7.33 | 9.8 |
| 2003 | 1,504 | 6 | 5.73 | 7.5 |
| 2002 | 2,357 | 11 | 7.43 | 9.8 |
| 2001 | 1,537 | 5 | 7.54 | 9.8 |
| 2000 | 1,236 | 0 | — | 0.0 |
| 1999 | 1,540 | 24 | 7.62 | 9.8 |
| Total | 372,344 | 200,913 | 6.87 | 10.0 |
The tables above are sliced from the derived reports in
report/ (sibling of data/) — see
report/README.md for methodology, the SINCE_DATE
cutoff, and how the top-10 markdown is sliced from the top-100 TSV.
| File | Format | Window |
|---|---|---|
report/cve.report.md |
Markdown table | all years |
report/cve.report.tsv |
TSV | all years |
| File | Format | Window |
|---|---|---|
report/cve.latest-10.report.md |
Markdown table | newest 10 CVEs |
report/cve.latest-10.report.tsv |
TSV | newest 10 CVEs |
| File | Axis | Window |
|---|---|---|
report/cwe.top100.by-cve-count.report.tsv |
CVE count | all years |
report/cwe.top100.by-cve-score.report.tsv |
avg score | all years |
report/cwe.top100.by-cve-count.since-2024.report.tsv |
CVE count | since 2024 |
report/cwe.top100.by-cve-score.since-2024.report.tsv |
avg score | since 2024 |
| File | Format |
|---|---|
report/cwe.report.md |
Markdown, two top-10 tables — the top-10 markdown is sliced from the two since-2024 TSVs above |
This repo is the producer: it reads
CVEProject/cvelistV5,
extracts a slim 9-column TSV per year, xz-compresses it, and publishes
the artifacts as GitHub Release assets
(https://github.com/x-cmd/cve/releases/download/data/<name>.xz).
The consumer is the x cve shell module,
which downloads on demand and never touches the upstream tree at runtime.
Companion module x cwe browses the CWE
catalog.
# 1. Browse — list / fzf over every cached CVE, newest first.
x cve
x cve fz
# 2. Look up a single CVE by id (or YYYY-NNNN shorthand).
x cve info CVE-2024-0001
x cve info 2024-0001 # same thing, no prefix needed
# 3. Pull the FULL upstream JSON record from CVEProject/cvelistV5:
# affected products, references, timeline, ADP containers, etc.
x cve detail CVE-2024-0001
# 4. Enrich with Shodan's CVE database — EPSS, KEV listing,
# exploit writeups, vendor advisories aggregated into one record:
x shodan cve CVE-2024-0001
# (https://x-cmd.com/mod/shodan/cve)x cve and x shodan cve chain cleanly:
x cve fz | x shodan cve - # preview every CVE in shodan
x shodan cve CVE-2024-0001 # equivalent, no pipe neededNo API keys, no sudo, no background services — x cve is a thin
shell module backed by the per-year TSVs this repo publishes daily.
.
├── .x-cmd/
│ ├── tsv.py # full rebuild from a local cvelistV5 clone
│ ├── cwe.py # MITRE CWE catalog mirror → data/cwe.tsv + .slim.tsv
│ ├── cwe_zh.py # MITRE Chinese mirror (cwe.org.cn) → data/cwe.zh.tsv (issue #2)
│ ├── cwe_report.py # aggregate data/cve-*.tsv ∩ data/cwe.slim.tsv (+ .zh.tsv) → report/cwe.report.{tsv,md,zh.md}
│ ├── report.py # per-year stats → report/cve.report.{tsv,md}
│ ├── latest.py # newest-N CVEs → report/cve.latest-N.report.{tsv,md}
│ └── _cve_index.py # shared parse / IO helpers
├── data/ # regenerated on every CI run — NOT in git
│ ├── cve-YYYY.tsv # one TSV per year (rows in DESCENDING cve-id order)
│ ├── index.tsv # year \t rows \t file
│ └── cve.tsv.state.json # per-file mtimes (for tsv.py incremental)
└── report/ # regenerated on every CI run — committed to main
├── README.md # docks the files + methodology
├── cve.report.{tsv,md} # per-year stats
├── cve.latest-10.report.{tsv,md} # newest 10 CVEs (front-of-page table)
├── cwe.top100.by-cve-count.report.tsv # all years, by count
├── cwe.top100.by-cve-score.report.tsv # all years, by score
├── cwe.top100.by-cve-count.since-2024.report.tsv # since 2024, by count
├── cwe.top100.by-cve-score.since-2024.report.tsv # since 2024, by score
├── cwe.report.md # English, since 2024, top-10 markdown
└── cwe.report.zh.md # Chinese, since 2024, top-10 markdown
├── README.cn.md # Chinese version of README.md (auto-updated)
└── .github/workflows/
└── release.yml # every 4h: tsv.py --rebuild → reports → xz → upload
data/ is regenerated from scratch on every CI run, so the working
tree on main stays small.
Every cve-YYYY.tsv is written with rows in descending cve-id order:
CVE-2026-99999
CVE-2026-99998
CVE-2026-99997
...
CVE-2026-00002
CVE-2026-00001
CVE-2025-99999
...
CVE-1999-00001
The x cve consumer walks year files in reverse (ls -r) and each
file is already in reverse order, so a plain cat produces
"newest CVE at the top of the stream". No tac, no second pass over
the data, no surprises.
Why store in reverse? x cve ls and x cve fz users care about
latest CVEs first — the freshly issued ones, today's score-bombs.
The producer's save_year_files sorts each bucket with
sort(reverse=True) so the on-disk order matches the display order.
| # | Column | Meaning |
|---|---|---|
| 1 | cve |
Full CVE id, e.g. CVE-2024-0001. |
| 2 | year |
Year segment parsed from the id. |
| 3 | no |
Numeric segment parsed from the id. |
| 4 | vp |
<vendor>/<product>;... from containers.cna.affected[], ;-joined. |
| 5 | ghsa |
GitHub Security Advisory id(s) in references, ;-joined. Empty if absent. |
| 6 | score |
Highest CVSS base score (v4.0 → v3.1 → v3.0 → v2.0, first hit wins). |
| 7 | patched |
1 if containers.cna.solutions[] is non-empty, else 0. |
| 8 | cwe |
CWE number(s) (prefix-stripped) joined with ;. Empty if absent. |
| 9 | desc |
English description, first sentence only (≤240 chars). |
Field 9 is truncated to the first sentence — Linux CNA routinely
pastes full kernel slab dumps (kilobytes of fp=0x... hex) into the
description field. Truncating keeps per-year files at ~1-9 MB each
and makes x cve fz lists scannable.
All scripts are dependency-free (Python 3.8+ stdlib). Run from the repo root:
# Full rebuild from a local cvelistV5 clone (~2 minutes for ~350k records)
python3 .x-cmd/tsv.py
# Force re-parse every file (ignore mtime state)
python3 .x-cmd/tsv.py --rebuild
# Fetch MITRE CWE catalog → data/cwe.tsv (full 21 columns) +
# data/cwe.slim.tsv (id+name only, used for joins).
python3 .x-cmd/cwe.py
# Fetch MITRE Chinese mirror (cwe.org.cn) → data/cwe.zh.tsv.
# 30-day local cache; on missing data the Chinese README falls
# back to English names (issue #2).
python3 .x-cmd/cwe_zh.py
# Aggregate cross-reference: how many CVEs reference each CWE,
# mean + max score. Reads data/cve-*.tsv + data/cwe.slim.tsv
# + data/cwe.zh.tsv.
python3 .x-cmd/cwe_report.py
# Newest-N CVEs (default 10) for the front-of-page table.
# Reads only the head of each per-year TSV.
python3 .x-cmd/latest.py
# Per-year stats → report/cve.report.{tsv,md}.
python3 .x-cmd/report.pyThe four report/cwe.*.report.tsv files are listed in the
Reports section above. Below are the two upstream CWE
catalog files this repo derives from MITRE:
| File | Shape | Source | Purpose |
|---|---|---|---|
data/cwe.tsv |
21-column TSV (~3 MB), all MITRE fields | Verbatim mirror of MITRE 2000.csv | x-cwe module + any consumer that wants the full CWE catalog without hitting MITRE directly |
data/cwe.slim.tsv |
2-column TSV (~50 KB), CWE-ID + Name only |
Derived from data/cwe.tsv |
Joined against data/cve-*.tsv for cwe_report.py |
| File | Shape | Source | Purpose |
|---|---|---|---|
data/cwe.tsv |
21-column TSV (~3 MB), all MITRE fields preserved | Verbatim mirror of MITRE 2000.csv (header row, spaces in column names replaced with _) |
x-cwe module and any consumer that wants the full CWE catalog without hitting MITRE directly |
data/cwe.slim.tsv |
2-column TSV (~50 KB), CWE-ID\tName only |
Derived from data/cwe.tsv (same row order) |
Joined against data/cve-*.tsv for cwe_report.py |
report/cwe.top100.by-cve-count.report.tsv |
5-column TSV (~6 KB), top 100 by CVE count, all years | Aggregated from data/cve-*.tsv ∩ data/cwe.slim.tsv |
Machine-readable top-N ranking |
report/cwe.top100.by-cve-score.report.tsv |
5-column TSV (~6 KB), top 100 by avg CVSS, all years | same | same |
report/cwe.top100.by-cve-count.since-2024.report.tsv |
5-column TSV (~6 KB), top 100 by CVE count, since 2024 | same, year >= 2024 | same |
report/cwe.top100.by-cve-score.since-2024.report.tsv |
5-column TSV (~6 KB), top 100 by avg CVSS, since 2024 | same, year >= 2024 | same |
report/cwe.report.md |
Markdown with two top-10 tables (since 2024) | Sliced from the two since-2024 TSVs | Stitches into the README + README.cn front-matter via release.yml's inline step |
Why we mirror the catalog: the upstream MITRE 2000.csv.zip is 644 KB and the unzipped csv is ~3 MB. xz-compressed to ~150 KB. We can afford to ship a full mirror, and it gives offline consumers the same data they'd get from MITRE without the network hop. The TSV keeps MITRE's column names (only spaces → underscores) so downstream code can use either format.
Why we don't ship a copy of the per-CVE catalog as a release
asset today: the x-cwe module currently fetches 2000.csv from
MITRE on its own and caches it locally (~/.x-cmd.root/local/data/cwe/).
A future version of x-cwe could optionally read data/cwe.tsv from
this repo's release instead, but that's not wired up yet.
.github/workflows/release.yml runs every 4 hours (37 minutes past
the hour, off-the-hour to spread load), plus on manual dispatch.
Each run:
- Clones CVEProject/cvelistV5 (depth 1) and runs
.x-cmd/tsv.py --rebuildto refreshdata/cve-*.tsv. - Regenerates
data/cwe.tsv+data/cwe.slim.tsvfrom MITRE (.x-cmd/cwe.py) and the CWE cross-reference report (.x-cmd/cwe_report.py→report/cwe.report.{tsv,md}). - Regenerates the year-stats report (
.x-cmd/report.py→report/cve.report.{tsv,md}). - Inlines both report markdown files into
README.mdas the first section (idempotent — BEGIN/END markers round-trip), then commitsREADME.md+ the four*.report.{md,tsv}back tomain(skip if nothing changed), so the README on github.com always tracks the latest data. - xz-compresses each changed per-year file (
xz -9, ~85% reduction), replaces the matching release asset, force-moves thedata-packagedgit tag so the next run's diff is correct.
No .xz files are committed to main — binaries live in release
assets, not source. The per-year data/cve-*.tsv and the CWE catalog
(data/cwe.tsv, data/cwe.slim.tsv) likewise stay out of git under
this flow; only the derived reports and the README are committed back,
keeping the git history focused on real code changes.
The workflow used to have a separate delta-update workflow that ran
on the same 4-hour cadence and produced an incremental data/cve.tsv;
its output was overwritten by step 1's full rebuild every time
release.yml followed via workflow_run, so the incremental work was
dead weight. See issue #1
for the numbers.
Apache License 2.0 — see LICENSE.
The underlying CVE records are derived from CVEProject/cvelistV5, which is released under CC BY 4.0. Downstream consumers of these TSVs must retain that attribution.
- x-cmd/cve module docs — consumer (shell)
- x-cmd/cwe module docs — companion module
- x-cmd/x-cmd — module source (
mod/cve/) - CVEProject/cvelistV5 — upstream data
CVE (Common Vulnerabilities and Exposures) is the public, free
catalog of every publicly disclosed computer-security vulnerability,
maintained by MITRE under funding from
the U.S. Department of Homeland Security. Each entry gets a unique
id (CVE-YYYY-NNNN) plus a short English description, a list of
affected vendor/products, a CVSS base score, and the weakness class
(CWE) the vuln maps to. As of 2026 the
catalog holds ~370,000 records going back to CVE-1999-0001.
CWE (Common Weakness Enumeration) is the taxonomy of software
weakness types — categories like "Cross-Site Scripting",
"Use After Free", "Path Traversal". A CVE points at one or more
CWE ids in its problemTypes[] array; this repo joins the two so
you can ask "how many XSS vulns shipped this year?" without
scanning 370k records by hand. MITRE's full CWE catalog lives at
data/cwe.tsv; the slim id→name join table is
data/cwe.slim.tsv.
- CVE = a specific instance of a bug (e.g. CVE-2026-90616: Flatpak before 1.18.1 has a sandbox-escape).
- CWE = the category of bug (e.g. CWE-22: Path Traversal).
A single CVE typically references one or more CWE ids that describe the class of weakness. CWE counts across CVEs are how this repo ranks "which mistakes keep happening most".
The Top 10 CWE by CVE count table at the top of this README shows what's getting shipped most since 2024. As of this run:
- CWE-79 — Cross-Site Scripting (XSS)
- CWE-89 — SQL Injection
- CWE-862 — Missing Authorization
- CWE-22 — Path Traversal
- CWE-94 — Code Injection
- CWE-78 — OS Command Injection
- CWE-416 — Use After Free
- CWE-20 — Improper Input Validation
- CWE-125 — Out-of-bounds Read
- CWE-352 — CSRF
XSS and SQLi have topped this list every year since CVE started.
For the top-100 (all years and since-2024 windows), see
report/cwe.top100.by-cve-count.report.tsv.
The Top 10 CWE by average CVSS score table ranks weakness types by the mean CVSS base score of the CVEs that reference them (with at least 10 samples to suppress single-CVE outliers). The head of this list tends to be dominated by:
- CWE-506 — Embedded Malicious Code
- CWE-95 — Eval Injection
- CWE-502 — Deserialization of Untrusted Data
- CWE-288 — Authentication Bypass via Alternate Channel
- CWE-121 — Stack-based Buffer Overflow
These are the classes that, when shipped, hurt the most. The
table is regenerated on every CI run — see
report/cwe.top100.by-cve-score.report.tsv
for the full top-100.
The 10 newest CVEs table at the very top of this README is
the front-of-page answer. It's regenerated every 4 hours directly
from MITRE's feed, so the table you see is at most a few hours
behind "right now". For the machine-readable top-N, see
report/cve.latest-10.report.tsv
or run python3 .x-cmd/latest.py N for any other N.
The "How fast is CVE growing?" table on this page answers that
question year-by-year with totals, scored count, and average /
max CVSS. The short answer: CVE volume has roughly doubled in
the past five years, with 2026 already past 56,000 records in
the first three quarters. Full per-year TSV lives at
report/cve.report.tsv.
For one record by id (e.g. CVE-2024-0001), the upstream
authority is the NVD detail page
(NIST). The repo's companion x cve
shell module gives you the same answer offline:
x cve info CVE-2024-0001
x cve info 2024-0001 # YYYY-NNNN shorthand works too
x cve detail CVE-2024-0001 # full upstream JSONx cve reads the per-year TSVs in this repo, so it works
air-gapped once the release asset has been fetched.
Three options, all free and unauthenticated:
# 1. One specific year (smallest payload, ~5 MB xz)
curl -fsSL https://github.com/x-cmd/cve/releases/download/data/cve-2026.tsv.xz | xz -dc > cve-2026.tsv
# 2. Whole catalog as a tarball (~21 MB xz)
curl -fsSL https://github.com/x-cmd/cve/releases/download/data/cve-all.tar.xz | tar -xJ
# 3. Just the CWE catalog (~150 KB xz, ~3 MB raw)
curl -fsSL https://github.com/x-cmd/cve/releases/download/data/cwe.tsv.xz | xz -dc > cwe.tsvEach asset is regenerated every 4 hours when upstream changes. Files are plain tab-separated TSVs — see TSV columns for the schema. No API key, no rate limit.
The TSV columns are documented under TSV columns. Because everything is plain text, standard Unix tooling is enough:
# All XSS CVEs scored >= 7.0 since 2024
xz -dc cve-2024.tsv xz -dc cve-2025.tsv xz -dc cve-2026.tsv 2>/dev/null | awk -F'\t' '$8 ~ /(^|;)79(;|$)/ && $6+0 >= 7'
# All CVEs affecting Apache HTTP Server in the current year
xz -dc cve-2026.tsv | awk -F'\t' '$4 ~ /Apache\/HTTP Server/ {print $1, $6, $9}'
# Top vendors by CVE count since 2024
xz -dc cve-2024.tsv xz -dc cve-2025.tsv xz -dc cve-2026.tsv 2>/dev/null | awk -F'\t' { for (i=1;i<=split($4,p,";");i++) print p[i] }' | sort | uniq -c | sort -rn | head -20The release includes pre-aggregated variants for the common
queries — see report/ for top-100 CWE rankings
by count and by score.
The Chinese names surfaced in the CWE ranking tables come from
cwe.org.cn — MITRE's official Chinese
mirror. The fetcher (.x-cmd/cwe_zh.py)
runs on every CI cycle and writes
data/cwe.zh.tsv (~91% coverage of the
969-entry catalog). The remaining 9% (mostly views and deprecated
ids) gracefully fall back to English names in the rendered
table — see issue #2.
Force a re-fetch with python3 .x-cmd/cwe_zh.py --force.