boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-912

Weakness type CWE-912 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
14113

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▃█▂▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 2 · 2026-08 6 · 2026-09 1 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-204399.899.9KEVCisco Smart Licensing Utility
CVE-2021-253716.155.1KEVSamsung Mobile Devices
CVE-2025-477291.934.8KEVTeleMessage TM SGNL
CVE-2026-615159.383.7—Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
CVE-2026-1481210.056.1—Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
CVE-2026-47699.353.6—Unauthenticated Access to Internal Diagnostic Interface
CVE-2026-181919.351.1—Vacron|IP Camera - Hidden Functionality
CVE-2026-318478.550.8—Hidden Functionality Enables Remote Telnet Activation via /goform/setSysTools in Nexxt …
CVE-2026-170329.843.8—Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
CVE-2026-1197610.042.3—MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
CVE-2026-1541310.042.3—Link Factory - Backdoor
CVE-2026-802178.741.5——
CVE-2026-828299.319.6—Hidden accounts or hard-coded credentials may permit unauthorized access without the le…
CVE-2026-188447.29.0—Pulsetto Vagus Nerve Stimulator Hidden Functionality

Most-affected vendors