{"success":true,"data":{"threats":[{"id":"b611e2f3-1086-40b1-8cf1-4014d7ae4e8e","slug":"cve-2026-84875","externalId":"CVE-2026-84875","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84875 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.","description":"IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.","cveId":"CVE-2026-84875","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:34.430Z","addedAt":"2026-10-08T23:06:40.648Z","updatedAt":"2026-10-08T23:06:40.648Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84875","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84875","note":"authoritative record"}]},{"id":"c1e2afd0-6b88-45af-b678-de40c056fcc3","slug":"cve-2026-84058","externalId":"CVE-2026-84058","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84058 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder.","description":"IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.","cveId":"CVE-2026-84058","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:33.313Z","addedAt":"2026-10-08T23:06:40.551Z","updatedAt":"2026-10-08T23:06:40.551Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84058","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84058","note":"authoritative record"}]},{"id":"19c01176-9114-4dc9-9f2b-d7ceefe4c896","slug":"cve-2026-82344","externalId":"CVE-2026-82344","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82344 — IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality.","description":"IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.","cveId":"CVE-2026-82344","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291670","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.020Z","addedAt":"2026-10-08T21:05:53.488Z","updatedAt":"2026-10-08T21:05:53.488Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82344","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82344","note":"authoritative record"}]},{"id":"0de67ead-c6ad-4260-85ce-cf214c9b617d","slug":"cve-2026-82335","externalId":"CVE-2026-82335","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82335 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser.","description":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution.","cveId":"CVE-2026-82335","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:36.873Z","addedAt":"2026-10-08T21:05:53.452Z","updatedAt":"2026-10-08T21:05:53.452Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82335","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82335","note":"authoritative record"}]},{"id":"ba3e23ba-3673-41d1-93e5-a9e0efb395a9","slug":"cve-2026-84290","externalId":"CVE-2026-84290","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84290 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver.","description":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-controlled pointers without adequate probing and exception handling, potentially allowing a privileged local attacker to cause a system crash or perform limited kernel-memory reads.","cveId":"CVE-2026-84290","cvssScore":5.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291676","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:20:51.530Z","addedAt":"2026-10-08T19:33:17.145Z","updatedAt":"2026-10-08T21:05:52.726Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84290","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84290","note":"authoritative record"}]},{"id":"209a5eea-9f9f-41c7-9fae-308d9e8284af","slug":"cve-2026-106067","externalId":"CVE-2026-106067","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106067 — A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in.","description":"A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size","cveId":"CVE-2026-106067","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106067","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547461","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00111,"epssPercentile":0.01226,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:16.173Z","addedAt":"2026-10-07T18:39:31.655Z","updatedAt":"2026-10-08T21:05:43.330Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106067","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106067","note":"authoritative record"}]},{"id":"4152f6a2-c37f-4b8d-8b47-8e67aa3048cb","slug":"cve-2026-106066","externalId":"CVE-2026-106066","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106066 — A heap-based buffer overflow was found in GIMP’s raw data export plug-in.","description":"A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow","cveId":"CVE-2026-106066","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106066","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547459","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00111,"epssPercentile":0.01226,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:16.013Z","addedAt":"2026-10-07T18:39:31.648Z","updatedAt":"2026-10-08T21:05:43.308Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106066","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106066","note":"authoritative record"}]},{"id":"67cd8e6b-0eda-4f8f-954f-f12bcb270b54","slug":"cve-2026-76464","externalId":"CVE-2026-76464","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76464 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensiv…","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119.","cveId":"CVE-2026-76464","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00192,"epssPercentile":0.081,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:59.053Z","addedAt":"2026-10-07T18:39:31.439Z","updatedAt":"2026-10-08T21:05:42.788Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76464","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76464","note":"authoritative record"}]},{"id":"8fb87a98-521b-4b73-be1a-94b8e619e4b2","slug":"cve-2026-106065","externalId":"CVE-2026-106065","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106065 — A heap-based buffer overflow was found in GIMP’s PCX export plug-in.","description":"A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation","cveId":"CVE-2026-106065","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106065","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547456","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00119,"epssPercentile":0.01609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:47.380Z","addedAt":"2026-10-07T18:39:31.268Z","updatedAt":"2026-10-08T21:05:42.360Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106065","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106065","note":"authoritative record"}]},{"id":"a18ae895-84c9-4922-a416-f0d6766cfdeb","slug":"cve-2026-107125","externalId":"CVE-2026-107125","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107125 — A flaw has been found in XnView Classic 2.52.5.","description":"A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.","cveId":"CVE-2026-107125","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119","CWE-122"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://newsgroup.xnview.com/viewtopic.php?t=51359","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-107125","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/993948","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://vuldb.com/vuln/414926","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/414926/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://www.xnview.com/en/xnview/#downloads","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00315,"epssPercentile":0.22396,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:18.440Z","addedAt":"2026-10-07T16:39:32.475Z","updatedAt":"2026-10-07T18:39:31.047Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107125","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107125","note":"authoritative record"}]},{"id":"191c1dac-02f2-4ae6-ba1f-4008e0d6e8b0","slug":"cve-2026-106064","externalId":"CVE-2026-106064","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106064 — A heap-based buffer overflow was found in GIMP’s GIF export plug-in.","description":"A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow","cveId":"CVE-2026-106064","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106064","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547446","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00111,"epssPercentile":0.01226,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:08.110Z","addedAt":"2026-10-07T16:39:32.406Z","updatedAt":"2026-10-07T20:39:40.177Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106064","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106064","note":"authoritative record"}]},{"id":"ace871df-e012-4976-a9c0-285bb18fdea1","slug":"cve-2026-106062","externalId":"CVE-2026-106062","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106062 — A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader.","description":"A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL, following integer overflow in size calculations. This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process.","cveId":"CVE-2026-106062","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106062","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2546654","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.0015,"epssPercentile":0.03635,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:04.903Z","addedAt":"2026-10-06T22:39:32.911Z","updatedAt":"2026-10-08T08:39:29.257Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106062","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106062","note":"authoritative record"}]},{"id":"2dbfbc7b-0a6c-4e9b-b48f-5dd7859b36d0","slug":"cve-2026-76745","externalId":"CVE-2026-76745","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76745 — Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker.","description":"Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.","cveId":"CVE-2026-76745","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05156en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00235,"epssPercentile":0.13265,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:29.840Z","addedAt":"2026-10-06T20:39:33.197Z","updatedAt":"2026-10-08T04:39:32.378Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76745","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76745","note":"authoritative record"}]},{"id":"4648cc50-58b5-4617-852e-cadbf6dbdc00","slug":"cve-2026-106063","externalId":"CVE-2026-106063","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106063 — A heap-based buffer overflow was found in GIMP’s DICOM export plug-in.","description":"A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer, after integer overflow in the allocation size","cveId":"CVE-2026-106063","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-106063","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2546668","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00119,"epssPercentile":0.01609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:17.090Z","addedAt":"2026-10-06T20:39:33.034Z","updatedAt":"2026-10-08T08:39:29.250Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106063","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106063","note":"authoritative record"}]},{"id":"64eb2678-95bb-47e2-8b75-ced76898955c","slug":"cve-2026-56936","externalId":"CVE-2026-56936","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-56936 — In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check.","description":"In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-56936","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01","type":"advisory","title":"dsap-vuln-management@google.com"}],"epssScore":0.00104,"epssPercentile":0.00941,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:15.093Z","addedAt":"2026-10-06T20:39:32.504Z","updatedAt":"2026-10-06T20:39:32.504Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56936","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-56936","note":"authoritative record"}]},{"id":"3007b2c7-8c1b-48b1-ae60-15839972dbfd","slug":"cve-2026-105778","externalId":"CVE-2026-105778","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105778 — A vulnerability has been found in Tenda AC5 02.03.01.111_multi.","description":"A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.","cveId":"CVE-2026-105778","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119","CWE-121"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/raisecnull/Tenda-AC5v3-BOF/blob/main/blog.md","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105778","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/992587","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413811","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413811/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://www.tenda.com.cn/","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00476,"epssPercentile":0.39162,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T07:16:56.547Z","addedAt":"2026-10-06T07:50:40.736Z","updatedAt":"2026-10-06T18:39:26.905Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105778","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105778","note":"authoritative record"}]},{"id":"f162a3a4-1b5e-4f50-bdd3-3f6a49d4f114","slug":"cve-2026-105775","externalId":"CVE-2026-105775","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105775 — A security vulnerability has been detected in vllm-project vLLM up to 0.31.0.","description":"A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cveId":"CVE-2026-105775","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119","CWE-125"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/vllm-project/vllm/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/vllm-project/vllm/issues/57266","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105775","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/992291","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413808","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413808/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00296,"epssPercentile":0.20406,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T06:17:00.280Z","addedAt":"2026-10-06T07:50:40.640Z","updatedAt":"2026-10-06T15:50:59.169Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105775","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105775","note":"authoritative record"}]},{"id":"64cc7ecd-aee1-4c78-bdaa-4da3828c1e9a","slug":"cve-2026-58865","externalId":"CVE-2026-58865","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58865 — In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check.","description":"In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58865","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0","17.0"],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00223,"epssPercentile":0.11885,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:25.183Z","addedAt":"2026-10-05T19:50:42.980Z","updatedAt":"2026-10-07T16:39:30.469Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58865","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58865","note":"authoritative record"}]},{"id":"aea029b6-093d-4944-bfbc-a986ccb0ae71","slug":"cve-2026-58856","externalId":"CVE-2026-58856","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58856 — In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check.","description":"In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58856","cvssScore":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0","17.0"],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00064,"epssPercentile":0.00012,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:24.967Z","addedAt":"2026-10-05T19:50:42.968Z","updatedAt":"2026-10-07T16:39:30.447Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58856","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58856","note":"authoritative record"}]},{"id":"b12ef193-468f-45aa-99ae-da89e2e697ec","slug":"cve-2026-58815","externalId":"CVE-2026-58815","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58815 — In multiple locations, there is a possible out of bounds write due to an incorrect bounds check.","description":"In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58815","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0","17.0"],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00073,"epssPercentile":0.0006,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:24.423Z","addedAt":"2026-10-05T19:50:42.942Z","updatedAt":"2026-10-07T16:39:30.392Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58815","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58815","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":836,"totalPages":42,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:17:41.822Z","durationMs":23,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-119"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}