Coverage and gaps
Generated from the current build — 5 September 2026
What this dataset contains, and more usefully what it does not. Every figure below is counted from the build rather than asserted, so it changes when the data does.
What is held
| Vendors tracked | 74 |
| Vendors with at least one CVE | 69 |
| Products with at least one CVE | 3293 |
| Vulnerabilities | 1279 |
| In CISA KEV | 22 |
Gaps in the vulnerability records
| CVEs with no CVSS score in NVD | 0 |
| CVEs with no EPSS score | 0 |
| Products whose device type could not be derived | 2853 |
| Products with no affected version recorded | 1021 |
| Products with exactly one CVE | 1262 |
Products in the last two rows carry thin pages. They are built so that links resolve, but most are excluded from search-engine indexing by the site's own quality threshold — a row in a database is not a reason to publish a page.
Vendors tracked with no CVEs found
These vendors are in scope and were queried. NVD returned no CVE naming their products in the CPE data. Read this carefully: for cloud-first vendors in particular, the absence reflects non-participation in the CVE system rather than an absence of vulnerabilities. A vendor that assigns no CVE identifiers produces an empty record here whatever its security history, so this list should be read as a statement about CVE participation and nothing else.
eufy / Anker · Western Digital · Ubiquiti · Xiaomi · DoorBird
Products excluded by the video filter
Vendors who also make routers, storage or building controls have their namespace filtered to video products only. These are the products that filter removed. If a camera or recorder is listed here, the filter is wrong and we would like to hear about it.
| Vendor | Excluded | Sample of excluded products |
|---|---|---|
| Schneider Electric | 1760 | 140_cpu6x, 140_cpu6x_firmware, 140_noc_77101, 140_noc_77101_firmware, 140_noc_78x00, 140_noc_78x00_firmware, 140_noe_771x1, 140_noe_771x1_firmware |
| NETGEAR | 1104 | 6r7500, 6r7500_firmware, ac1200_r6220, ac1200_r6220_firmware, ac1450, ac1450_firmware, ac2100, ac2100_firmware |
| TP-Link | 1030 | 8840t, ac1750, ac1750_firmware, aginet, archer-c3150, archer-c3150_firmware, archer_a10, archer_a10_firmware |
| D-Link | 847 | 6600-ap, 6600-ap_firmware, central_wifimanager, covr-2600r, covr-2600r_firmware, covr-3902, covr-3902_firmware, covr-x1870 |
| Honeywell | 369 | ademco_atnbaseloader100_module, alerton_ascent_control_module, alerton_ascent_control_module_firmware, alerton_bcm-web, alerton_bcm-web_firmware, alerton_compass, alterton_visual_logic, alterton_visual_logic_firmware |
| Tenda | 204 | 11n, 11n_firmware, 4g03_pro, 4g03_pro_firmware, 4g06, 4g06_firmware, 4g300, 4g300_firmware |
| QNAP | 132 | ai_core, authenticator, container_station, download_station, ej1600, ej1600_firmware, file_station, helpdesk |
| Bosch | 124 | access, access_easy_controller, access_easy_controller_firmware, access_management_system, access_professional_edition, amc2, amc2_firmware, b420 |
| TRENDnet | 110 | teg-30102ws, teg-30102ws_firmware, teg-40128, teg-40128_firmware, tew-410apb, tew-410apb_firmware, tew-411brpplus, tew-411brpplus_firmware |
| Johnson Controls | 104 | ac2000, ac2000_firmware, application_and_data_server, bcpro, c-cure_9000, c-cure_9000_firmware, c-cure_web, cevas |
| Synology | 96 | active_backup_for_business, active_backup_for_business_agent, active_backup_for_business_recovery_media_creator, active_backup_for_microsoft_365, activeprotect_agent, antivirus_essential, application_service, assistant |
| Realtek | 68 | adsl_router_soc_firmware, audio_driver_firmware, bluetooth_mesh_software_development_kit, ecos_msdk, ecos_msdk_firmware, ecos_rsdk, ecos_rsdk_firmware, hd_audio_codec_drivers |
| Panasonic | 52 | aiseg2, aiseg2_firmware, arbitrator_back-end_server_mk_2.0_vpu, arbitrator_back-end_server_mk_2.0_vpu_firmware, arbitrator_back-end_server_mk_3.0_vpu, arbitrator_back-end_server_mk_3.0_vpu_firmware, bb_hcm511, bb_hcm515 |
| Edimax | 37 | 6114wg, 6114wg_router_firmware, 7237rpd, 7237rpd_firmware, br-6104k, br-6104k_router_firmware, br-6208ac, br-6208ac_firmware |
| Western Digital | 26 | ibi, my_cloud, my_cloud_dl2100, my_cloud_dl4100, my_cloud_dl4100_firmware, my_cloud_ex2, my_cloud_ex2100, my_cloud_ex2100_firmware |
| Aqara | 11 | board_service, cloud_developer_portal, cloud_oauth_authorization_endpoint, cloud_production_api, developer_portal, home, hub_m2, hub_m2_firmware |
| Ubiquiti | 7 | airos_4_xs2, airos_4_xs5, edgeos, edgeswitch, edgeswitch_firmware, edgeswitch_xp_firmware, ucrm |
| eufy / Anker | 6 | eufy_homebase_2, eufy_homebase_2_firmware, homebase_2, homebase_2_firmware, nebula_capsule_projector, nebula_capsule_projector_firmware |
| Xiaomi | 2 | fileexplorer, mitalk_messenger |
Fetch errors in this build
None. Every vendor namespace in scope returned a complete result set.
Known structural limits
Four, none of which we can fix from public data.
Vendors who do not assign CVEs are invisible here. A vendor that fixes issues in a firmware release without publishing an identifier produces no record anywhere, and no amount of care in this pipeline will surface it.
Component vulnerabilities are not attributed to devices. Where a camera embeds a vulnerable library, the CVE names the library. Unless the device vendor publishes its own advisory, nothing connects the two. This site tracks several such components as vendors in their own right, which is the closest approximation available.
CPE data is incomplete and inconsistent. Some CVE records name a vendor without enumerating models. Those CVEs appear against fewer products than they actually affect.
There is no lifecycle data. End-of-support is frequently the most decisive fact about a device's risk, and no public machine-readable source for it exists across these vendors.
Counts generated at build time from data/build/dataset.json. Method: methodology.