Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Cybersecurity Vulnerability Intelligence: CVE, KEV, EPSS and PoC Tracking

A focused English hub for security teams tracking high-risk vulnerabilities, known exploited CVEs, exploitation probability, public exploit mappings, proof-of-concept availability, affected products and mitigation references.

Vendor Vulnerability Hubs

Recently Published Critical CVEs

12 CVEs
CVE Title CVSS Vendor Published
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection - CP3 CWE-78 9.1 Tenda 2026-09-05
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection - CP3 CWE-78 9.1 Tenda 2026-09-05
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection - CP3 CWE-78 9.1 Tenda 2026-09-05
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS - RouterOS CWE-88 9.2 Mikrotik 2026-09-05
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS - RouterOS CWE-347 9.2 Mikrotik 2026-09-05
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter - AVideo CWE-200 9.1 WWBN 2026-09-05
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php - AVideo CWE-73 9.8 WWBN 2026-09-05
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route - laradashboard CWE-306 9.8 laradashboard 2026-09-05
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields - Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails CWE-502 9.8 getwpfunnels 2026-09-05
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server - AutoAgent CWE-306 9.8 HKUDS 2026-09-05
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control - cua-computer-server CWE-306 9.8 trycua 2026-09-05
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection - Post Grid CWE-94 9.8 pickplugins 2026-09-05

Live Vulnerability Queues

How to use this vulnerability intelligence hub

Start with KEV and EPSS when prioritizing emergency patching. Use public exploit mappings and PoC pages to understand exploit availability, then open the CVE detail page for CVSS vectors, affected versions, CWE classification, references, AI deep analysis and mitigation context.