Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-300
Weakness type CWE-300 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 6 | 6 | 0 |
Monthly trend
▃▆█▁
2026-07 1 · 2026-08 2 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-74232 | 9.3 | 55.7 | — | Zbtlink MQWrt yunmgrd Cloud C2 Implant |
| CVE-2026-84197 | 9.2 | 25.8 | — | — |
| CVE-2026-97866 | 2.9 | 16.4 | — | Zhonglun CloudPOS Automatic Update Program.cs channel accessible |
| CVE-2026-76715 | 7.1 | 16.1 | — | Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability i… |
| CVE-2026-12991 | 8.7 | 11.3 | — | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2025-29419 | 7.1 | 7.5 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| eclipse foundation | 1 |
| ghost robotics | 1 |
| hewlett packard enterprise (hpe) | 1 |
| morequick | 1 |
| zbtlink | 1 |
| zhonglun | 1 |