CWE-912Class3 in KEV

Hidden Functionality

Incomplete in the CWE catalog · 79 CVEs mapped

79
CVEs mapped
3
In KEV
7.9
Median CVSS
What it is

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

Recent examples
10.0cvss
CVE-2026-15413

CVE-2026-15413 - CRITICAL Severity Vulnerability

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).

CRITICALno explanation yet
0%
epss
8.1cvss
CVE-2026-18844

CVE-2026-18844 - HIGH Severity Vulnerability

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.

HIGHno explanation yet
0%
epss
9.8cvss
CVE-2026-17032

CVE-2026-17032 - CRITICAL Severity Vulnerability

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-912
Abstraction
Class
Structure
Simple
Status
Incomplete