Threats Tagged 'cwe-912'
View all threats tagged with 'cwe-912'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-912'
Click on any threat for detailed analysis and mitigation recommendations
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated… (CVE-2026-17032)CVE-2026-17032 0 Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites. Join the discussion | GCVE Database | 08/07/2026, 00:31:15 UTC Added: 08/07/2026, 05:56:53 UTC |
CVE-2026-14812: CWE-912 Hidden Functionality in Premium SEOCVE-2026-14812 0 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site. Join the discussion | CVE Database V5 | 08/06/2026, 16:52:36 UTC Added: 08/06/2026, 22:13:07 UTC |
CVE-2026-11976: CWE-912 Hidden Functionality in MonsterInsights ProCVE-2026-11976 0 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day. Join the discussion | CVE Database V5 | 08/06/2026, 16:40:18 UTC Added: 08/06/2026, 22:13:07 UTC |
CVE-2026-18191: CWE-912 Hidden Functionality in Vacron VIN-DS783E-E6CVE-2026-18191 0 Vacron VIN-DS783E-E6 contains a critical hidden functionality vulnerability (CWE-912) that allows unauthenticated remote attackers to access a concealed function and obtain administrator credentials. This vulnerability has a CVSS 4.0 score of 9.3, indicating high severity and ease of exploitation without user interaction or privileges. No patch or official remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 07/29/2026, 06:36:50 UTC Added: 07/29/2026, 07:37:43 UTC |
CVE-2026-4769: CWE-912 Hidden Functionality in WAGO 0765-110x/0100-0000CVE-2026-4769 0 Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise. Join the discussion | CVE Database V5 | 07/13/2026, 06:35:01 UTC Added: 07/13/2026, 07:51:42 UTC |
CVE-2026-12685: CWE-912 Hidden Functionality in escortwpCVE-2026-12685 0 The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server. Join the discussion | CVE Database V5 | 07/10/2026, 06:00:02 UTC Added: 07/10/2026, 06:33:05 UTC |
Showing 1 to 6 of 6 results