| CVE-2026-86164 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86163 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.p | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86162 | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=log | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86161 | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?acti | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86160 | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86159 | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. Th | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86153 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Red | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-86152 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddW | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-86151 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the comp | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-85038 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does n | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-84219 | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthent | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84028 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attri | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-80439 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-80437 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when i | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-75816 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-75793 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowin | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-19862 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-19859 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing un | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-18480 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-18056 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up t | — | 2026-09-06 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-16310 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'i | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-13159 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authe | — | 2026-09-06 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2022-51009 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attac | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2022-51008 | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2021-48007 | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2021-48006 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function low | — | 2026-09-06 | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Local
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2020-37277 | PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() meth | — | 2026-09-06 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-8625 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-8623 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-86207 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- Present
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86206 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86197 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- Passive
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- Low
SASubsequent System Availability- None
| — |
| CVE-2026-86196 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing u | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86195 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86194 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86193 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user manager | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86192 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish reade | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86191 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish r | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86190 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86189 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitr | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |