CVE ID :CVE-2026-86151 Published : Sept. 6, 2026, 12:16 a.m. | 21 minutes ago Description :A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file…
CVE-2026-86149 – Tenda CP3 NetCheckPing.cpp os command injection
CVE ID :CVE-2026-86149 Published : Sept. 5, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the…
CVE-2026-86148 – Tenda CP3 Kylin system.c SystemAsh os command injection
CVE ID :CVE-2026-86148 Published : Sept. 5, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of…
CVE-2026-86060 – SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE ID :CVE-2026-86060 Published : Sept. 5, 2026, 8:17 p.m. | 4 hours, 20 minutes ago Description :RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited…
CVE-2026-67281 – Unauthenticated file read in Mikrotik RouterOS
CVE ID :CVE-2026-67281 Published : Sept. 5, 2026, 8:17 p.m. | 4 hours, 20 minutes ago Description :RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains…
CVE-2026-52777 – YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
CVE ID :CVE-2026-52777 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object…
CVE-2026-52775 – YesWiki Authenticated SQL Injection in ReactionManager
CVE ID :CVE-2026-52775 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch…
CVE-2026-52771 – YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
CVE ID :CVE-2026-52771 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a…
CVE-2026-52769 – YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
CVE ID :CVE-2026-52769 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox…
CVE-2026-52767 – YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(…)` accepting `int(-1)`
CVE ID :CVE-2026-52767 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the…