| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-86299 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | Linksys | RE7000 | Critical | 9.9 | 2026-09-07 11:15:08 | Deep Dive |
| CVE-2026-86296 | D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow | D-Link | DIR-822A | Critical | 10.0 | 2026-09-07 10:30:09 | Deep Dive |
| CVE-2026-79698 | Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection | Advantech | WISE-6610-NB | Critical | 9.9 | 2026-09-07 06:30:42 | Deep Dive |
| CVE-2026-79697 | Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection | Advantech | WISE-6610-NB | Critical | 9.9 | 2026-09-07 06:15:42 | Deep Dive |
| CVE-2026-16876 | NEC UNIVERGE IX-R/IX-V 授权问题漏洞 | NEC Corporation | UNIVERGE IX-R/IX-V | Critical | 9.3 | 2026-09-07 00:48:01 | Deep Dive |
| CVE-2026-86167 | Tenda HG10 Boa formgponConf os command injection | Tenda | HG10 | Critical | 9.9 | 2026-09-06 04:30:13 | Deep Dive |
| CVE-2026-86165 | Tenda HG10 formURL buffer overflow | Tenda | HG10 | Critical | 9.8 | 2026-09-06 03:30:09 | Deep Dive |
| CVE-2026-75816 | Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier | shabti | Frontend Admin by DynamiApps | Critical | 9.8 | 2026-09-06 02:26:52 | Deep Dive |
| CVE-2026-16310 | MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter | LearnDash | MemberDash | Critical | 9.8 | 2026-09-06 02:26:51 | Deep Dive |
| CVE-2026-86218 KEV 📌 💣 | pre-authentication remote code execution | N-able | N-central | Critical | 10.0 | 2026-09-06 02:15:29 | Deep Dive |
| CVE-2026-86153 | Tenda CP3 Redirect.cpp SetRedirectEnable privileges management | Tenda | CP3 | Critical | 9.1 | 2026-09-06 01:45:15 | Deep Dive |
| CVE-2026-86152 | Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection | Tenda | CP3 | Critical | 10.0 | 2026-09-06 01:30:11 | Deep Dive |
| CVE-2026-86151 | Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection | Tenda | CP3 | Critical | 9.1 | 2026-09-05 23:45:09 | Deep Dive |
| CVE-2026-86149 | Tenda CP3 NetCheckPing.cpp os command injection | Tenda | CP3 | Critical | 9.1 | 2026-09-05 22:00:10 | Deep Dive |
| CVE-2026-86148 | Tenda CP3 Kylin system.c SystemAsh os command injection | Tenda | CP3 | Critical | 9.1 | 2026-09-05 21:45:10 | Deep Dive |
| CVE-2026-86060 KEV | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS | Mikrotik | RouterOS | Critical | 9.2 | 2026-09-05 20:00:59 | Deep Dive |
| CVE-2026-67276 | SSH user impersonation possible in Mikrotik RouterOS | Mikrotik | RouterOS | Critical | 9.2 | 2026-09-05 20:00:56 | Deep Dive |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | WWBN | AVideo | Critical | 9.8 | 2026-09-05 12:09:05 | Deep Dive |
| CVE-2026-86190 | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter | WWBN | AVideo | Critical | 9.1 | 2026-09-05 12:09:05 | Deep Dive |
| CVE-2026-86184 | Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route | laradashboard | laradashboard | Critical | 9.8 | 2026-09-05 11:38:01 | Deep Dive |