Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-912 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
▂▁▁▁▃█
2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 2 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-61515 | 9.3 | 73.5 | — | Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell |
| CVE-2026-14812 | 10.0 | 44.6 | — | Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) |
| CVE-2026-11976 | 10.0 | 40.0 | — | MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise |
| CVE-2026-4769 | 9.3 | 37.4 | — | Unauthenticated Access to Internal Diagnostic Interface |
| CVE-2026-31847 | 8.5 | 35.6 | — | Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt … |
| CVE-2026-18191 | 9.3 | 31.6 | — | Vacron|IP Camera - Hidden Functionality |
| CVE-2026-17032 | 9.8 | 30.7 | — | Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server |
| CVE-2026-15413 | 10.0 | 21.6 | — | Link Factory - Backdoor |
| CVE-2026-18844 | 7.2 | 3.3 | — | Pulsetto Vagus Nerve Stimulator Hidden Functionality |
| Vendor | CVEs |
|---|---|
| nexxt solutions | 1 |
| pulsetto | 1 |
| puwell technology | 1 |
| vacron | 1 |
| wago | 1 |