boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-912

Weakness type CWE-912 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

▂▁▁▁▃█

2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 2 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-615159.373.5Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
CVE-2026-1481210.044.6Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
CVE-2026-1197610.040.0MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
CVE-2026-47699.337.4Unauthenticated Access to Internal Diagnostic Interface
CVE-2026-318478.535.6Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt …
CVE-2026-181919.331.6Vacron|IP Camera - Hidden Functionality
CVE-2026-170329.830.7Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
CVE-2026-1541310.021.6Link Factory - Backdoor
CVE-2026-188447.23.3Pulsetto Vagus Nerve Stimulator Hidden Functionality

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
nexxt solutions1
pulsetto1
puwell technology1
vacron1
wago1