Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-86165 — Tenda HG10 formURL buffer overflow

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results …

hg10 | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
10.0 CRITICAL
CVE-2026-86218 — pre-authentication remote code execution

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

n-central | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86162 — SourceCodester Online Voting System ajax.php login sql injection

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can l…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86161 — SourceCodester Online Voting System ajax.php delete_category sql injection

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argume…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86160 — SourceCodester Online Voting System ajax.php delete_voting sql injection

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86159 — SourceCodester Online Voting System ajax.php save_user sql injection

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. Th…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.8 CRITICAL
CVE-2026-75816 — Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_obje…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value fun…

Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-18056 — HivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_tok…

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_us…

Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.8 CRITICAL
CVE-2026-16310 — MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Referen…

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled…

Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-86164 — itsourcecode Sales and Inventory System trans_view.php sql injection

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in s…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-86163 — itsourcecode Sales and Inventory System pro_del.php sql injection

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql inject…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.4 CRITICAL
CVE-2026-86153 — Tenda CP3 Redirect.cpp SetRedirectEnable privileges management

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege man…

cp3 | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
10.0 CRITICAL
CVE-2026-86152 — Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation ca…

cp3 | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.4 CRITICAL
CVE-2026-86151 — Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipu…

cp3_firmware cp3 | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.1 MEDIUM
CVE-2026-86150 — Tenda CP3 hostapd hard-coded credentials

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to har…

cp3_firmware cp3 | Remote | Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
9.4 CRITICAL
CVE-2026-86149 — Tenda CP3 NetCheckPing.cpp os command injection

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os c…

cp3_firmware cp3 | Remote | Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
9.4 CRITICAL
CVE-2026-86148 — Tenda CP3 Kylin system.c SystemAsh os command injection

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument Alar…

cp3_firmware cp3 | Remote | Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.9 MEDIUM
CVE-2026-86206 — Access control filter bypass allows unauthorised access to APIs

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

n-central | Remote | Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
9.2 CRITICAL
CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to p…

routeros routeros | Remote | Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
8.7 HIGH
CVE-2026-67281 — Unauthenticated file read in Mikrotik RouterOS

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. A…

routeros routeros | Remote | Path Traversal
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
Showing 20 of 12429 Results