Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41870
Total
3419
Critical
12379
High
12272
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86166 | HIGH | 8.8 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing … | Sep 06, 2026 |
| CVE-2026-86165 | CRITICAL | 9.8 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN … | Sep 06, 2026 |
| CVE-2026-86164 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of … | Sep 06, 2026 |
| CVE-2026-86163 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument … | Sep 06, 2026 |
| CVE-2026-86218 | UNKNOWN | — | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | Sep 06, 2026 |
| CVE-2026-86162 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument … | Sep 06, 2026 |
| CVE-2026-86161 | HIGH | 7.3 | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of … | Sep 06, 2026 |
| CVE-2026-86160 | HIGH | 7.3 | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of … | Sep 06, 2026 |
| CVE-2026-86159 | HIGH | 7.3 | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument … | Sep 06, 2026 |
| CVE-2026-75816 | CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This … | Sep 06, 2026 |
| CVE-2026-18056 | HIGH | 7.5 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is … | Sep 06, 2026 |
| CVE-2026-16310 | CRITICAL | 9.8 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due … | Sep 06, 2026 |
| CVE-2026-86153 | CRITICAL | 9.1 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. … | Sep 06, 2026 |
| CVE-2026-86152 | CRITICAL | 10.0 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing … | Sep 06, 2026 |
| CVE-2026-86151 | CRITICAL | 9.1 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. … | Sep 06, 2026 |
| CVE-2026-86150 | MEDIUM | 4.1 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase … | Sep 05, 2026 |
| CVE-2026-76161 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 05, 2026 |
| CVE-2026-76160 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 05, 2026 |
| CVE-2026-86149 | CRITICAL | 9.1 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host … | Sep 05, 2026 |
| CVE-2026-86148 | CRITICAL | 9.1 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The … | Sep 05, 2026 |
| CVE-2026-86206 | UNKNOWN | — | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 | Sep 05, 2026 |
| CVE-2026-86060 | UNKNOWN | — | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask … | Sep 05, 2026 |
| CVE-2026-67281 | UNKNOWN | — | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file … | Sep 05, 2026 |
| CVE-2026-67279 | UNKNOWN | — | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session … | Sep 05, 2026 |
| CVE-2026-67278 | UNKNOWN | — | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an … | Sep 05, 2026 |