| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | Acronis | 2026-09-17 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-16 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | Cisco | 2026-09-16 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-16 |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | Google | 2026-09-15 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Adjacent
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-16 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | Cisco | 2026-09-14 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-14 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | Gitlab | 2026-09-12 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- High
AAvailability- None
| 2026-09-11 |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | Google | 2026-09-09 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-09 |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Microsoft | 2026-09-08 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-08 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | Connectwise | 2026-09-08 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-11 |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | Microsoft | 2026-09-08 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-08 |
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Adobe | 2026-09-07 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- High
AAvailability- High
| 2026-09-08 |
| CVE-2026-86257 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject s | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- Active
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- Low
SASubsequent System Availability- None
| — |
| CVE-2026-86256 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). Af | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- Passive
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- Low
SASubsequent System Availability- None
| — |
| CVE-2026-86255 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbi | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86254 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym | — | 2026-09-06 | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86253 | h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname | — | 2026-09-06 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86252 | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject a | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86251 | h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path co | — | 2026-09-06 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86250 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteCh | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86242 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins whe | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | N-able | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| 2026-09-08 |
| CVE-2026-86214 | A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86213 | A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/universi | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86212 | A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation le | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86211 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the compone | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86210 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unk | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86209 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_ | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86208 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /d | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86205 | h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86183 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/d | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86182 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/ | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86181 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /use | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- Passive
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86180 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionalit | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86179 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak. | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86172 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Perfor | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86171 | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete. | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86170 | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86168 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86167 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-86166 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86165 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Perfo | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |