{"success":true,"data":{"threats":[{"id":"6b050018-7d03-4de9-91da-9dba31dd8a1a","slug":"cve-2026-107651","externalId":"CVE-2026-107651","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107651 — A flaw was found in Eye of GNOME (eog).","description":"A flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash.","cveId":"CVE-2026-107651","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107651","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547986","type":"advisory","title":"secalert@redhat.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T23:16:57.863Z","addedAt":"2026-10-09T01:06:18.589Z","updatedAt":"2026-10-09T01:06:18.589Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107651","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107651","note":"authoritative record"}]},{"id":"4e604934-5b18-4a56-819e-58b0546a601d","slug":"cve-2026-106177","externalId":"CVE-2026-106177","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106177 — A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution.","description":"A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.","cveId":"CVE-2026-106177","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hp.com/us-en/document/ish_15759419-15759442-16/hpsbhf04157","type":"advisory","title":"hp-security-alert@hp.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:01.777Z","addedAt":"2026-10-08T16:39:36.001Z","updatedAt":"2026-10-08T23:06:38.373Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106177","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106177","note":"authoritative record"}]},{"id":"93dffe42-8a77-4d74-849a-2b6bc510315b","slug":"cve-2026-14888","externalId":"CVE-2026-14888","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14888 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.","cveId":"CVE-2026-14888","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:49.700Z","addedAt":"2026-10-08T16:39:35.935Z","updatedAt":"2026-10-08T21:05:50.476Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14888","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14888","note":"authoritative record"}]},{"id":"3e9b6a27-a839-45d7-a578-86163135614a","slug":"cve-2026-14269","externalId":"CVE-2026-14269","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14269 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.","cveId":"CVE-2026-14269","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:48.600Z","addedAt":"2026-10-08T16:39:35.871Z","updatedAt":"2026-10-08T21:05:50.202Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14269","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14269","note":"authoritative record"}]},{"id":"56d26cd5-1522-4ecb-b19a-7061573d8226","slug":"cve-2026-105401","externalId":"CVE-2026-105401","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105401 — ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to o…","description":"ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attackers can connect to the distributed pixel cache server and transmit malicious data to trigger a heap buffer over-write that crashes the server, causing denial of service.","cveId":"CVE-2026-105401","cvssScore":6,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-heap-buffer-overflow-in-distributed-pixel-cache-server","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:33.310Z","addedAt":"2026-10-08T16:39:35.614Z","updatedAt":"2026-10-08T21:05:49.701Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105401","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105401","note":"authoritative record"}]},{"id":"f553e308-fe1e-4bb5-b990-943bbe41e0fd","slug":"cve-2026-103011","externalId":"CVE-2026-103011","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103011 — Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hM…","description":"Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.","cveId":"CVE-2026-103011","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/49","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:42.270Z","addedAt":"2026-10-08T12:39:41.222Z","updatedAt":"2026-10-08T23:06:37.424Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103011","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103011","note":"authoritative record"}]},{"id":"3329c015-8f51-4737-8292-0c30d995d723","slug":"cve-2026-103010","externalId":"CVE-2026-103010","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103010 — Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 …","description":"Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.","cveId":"CVE-2026-103010","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/commit/135a1908ff820ed587d5f180f98c53bd010d8931","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.4","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/49","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:42.117Z","addedAt":"2026-10-08T12:39:41.213Z","updatedAt":"2026-10-08T23:06:37.405Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103010","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103010","note":"authoritative record"}]},{"id":"9505e19a-dca6-4d93-83d4-c2e78941bc57","slug":"cve-2026-87679","externalId":"CVE-2026-87679","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87679 — When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dyna…","description":"When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability via crafted REST API requests containing an excessive number of list delimiters, causing heap corruption that can result in service crash or arbitrary code execution.","cveId":"CVE-2026-87679","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39073","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00161,"epssPercentile":0.0473,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T01:16:32.313Z","addedAt":"2026-10-08T02:39:29.909Z","updatedAt":"2026-10-08T21:05:45.303Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87679","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87679","note":"authoritative record"}]},{"id":"90b9cea4-77cb-451a-a0ad-d6179a6dafc0","slug":"cve-2026-107161","externalId":"CVE-2026-107161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107161 — A heap-based buffer overflow flaw was found in Cyrus SASL.","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.","cveId":"CVE-2026-107161","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107161","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460420","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00238,"epssPercentile":0.136,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:10.977Z","addedAt":"2026-10-07T20:39:40.461Z","updatedAt":"2026-10-08T21:05:43.868Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107161","note":"authoritative record"}]},{"id":"ce57990a-7285-43c4-8e56-4feb12cb56f1","slug":"cve-2026-76471","externalId":"CVE-2026-76471","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76471 — A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root p…","description":"A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.","cveId":"CVE-2026-76471","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00523,"epssPercentile":0.42561,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:00.230Z","addedAt":"2026-10-07T18:39:31.488Z","updatedAt":"2026-10-08T21:05:42.904Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76471","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76471","note":"authoritative record"}]},{"id":"dcc5b659-c82b-4a19-a4fe-d3a3093a1d4a","slug":"cve-2026-106574","externalId":"CVE-2026-106574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106574 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31.","cveId":"CVE-2026-106574","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122","CWE-125","CWE-131","CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00201,"epssPercentile":0.09186,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:43.467Z","addedAt":"2026-10-07T16:39:32.614Z","updatedAt":"2026-10-08T21:05:42.126Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106574","note":"authoritative record"}]},{"id":"af385b0b-31ea-448f-bb95-6cc80add5a69","slug":"cve-2026-106564","externalId":"CVE-2026-106564","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106564 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32.","cveId":"CVE-2026-106564","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122","CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/f7437ebafcd92d6959eca4086d80b150d52bdb7c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54rx-5x9g-g465","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00372,"epssPercentile":0.29018,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:40.430Z","addedAt":"2026-10-07T16:39:32.539Z","updatedAt":"2026-10-08T21:05:41.867Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106564","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106564","note":"authoritative record"}]},{"id":"c3fe01a2-53f3-44ed-9c8b-a799bd5055e2","slug":"cve-2026-46570","externalId":"CVE-2026-46570","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46570 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap m…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.","cveId":"CVE-2026-46570","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-m6qq-pv5j-2wxc"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-m6qq-pv5j-2wxc","type":"patch","title":"Patch"}],"epssScore":0.00128,"epssPercentile":0.02135,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:21.010Z","addedAt":"2026-10-07T16:39:32.516Z","updatedAt":"2026-10-08T19:33:16.617Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46570","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46570","note":"authoritative record"}]},{"id":"a18ae895-84c9-4922-a416-f0d6766cfdeb","slug":"cve-2026-107125","externalId":"CVE-2026-107125","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107125 — A flaw has been found in XnView Classic 2.52.5.","description":"A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.","cveId":"CVE-2026-107125","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119","CWE-122"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://newsgroup.xnview.com/viewtopic.php?t=51359","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-107125","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/993948","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://vuldb.com/vuln/414926","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/414926/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://www.xnview.com/en/xnview/#downloads","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00315,"epssPercentile":0.22396,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:18.440Z","addedAt":"2026-10-07T16:39:32.475Z","updatedAt":"2026-10-07T18:39:31.047Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107125","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107125","note":"authoritative record"}]},{"id":"306f6b6a-8883-475c-9fe9-17c79af42c6f","slug":"cve-2026-46572","externalId":"CVE-2026-46572","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46572 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memor…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.","cveId":"CVE-2026-46572","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-wx5r-gc7w-9hhc"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-wx5r-gc7w-9hhc","type":"patch","title":"Patch"}],"epssScore":0.00128,"epssPercentile":0.02135,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:11.470Z","addedAt":"2026-10-07T14:39:35.296Z","updatedAt":"2026-10-08T19:33:16.600Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46572","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46572","note":"authoritative record"}]},{"id":"13666092-2b6e-4831-8f17-e6ba4f9e61ab","slug":"cve-2026-42618","externalId":"CVE-2026-42618","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42618 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap me…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.","cveId":"CVE-2026-42618","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122","CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw","type":"patch","title":"Patch"}],"epssScore":0.00126,"epssPercentile":0.02033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.740Z","addedAt":"2026-10-07T14:39:35.233Z","updatedAt":"2026-10-08T19:33:16.540Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42618","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42618","note":"authoritative record"}]},{"id":"1c8bfd16-8fa0-49d7-800a-959788f24088","slug":"cve-2026-42617","externalId":"CVE-2026-42617","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42617 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.","cveId":"CVE-2026-42617","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-jv65-qqf7-f692"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-jv65-qqf7-f692","type":"patch","title":"Patch"}],"epssScore":0.00126,"epssPercentile":0.02033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.587Z","addedAt":"2026-10-07T14:39:35.226Z","updatedAt":"2026-10-08T19:33:16.520Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42617","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42617","note":"authoritative record"}]},{"id":"c9df30ad-f578-416e-afaf-d5d86c433a11","slug":"cve-2026-106547","externalId":"CVE-2026-106547","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106547 — A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly…","description":"A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file.","cveId":"CVE-2026-106547","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/HDFGroup/hdf5/pull/6529","type":"advisory","title":"0253b833-3e77-4dfe-9d57-17db1a2f0a74"}],"epssScore":0.00163,"epssPercentile":0.0497,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:18.670Z","addedAt":"2026-10-06T22:39:33.053Z","updatedAt":"2026-10-07T16:39:31.265Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106547","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106547","note":"authoritative record"}]},{"id":"cbedccd1-05e7-4c69-a6de-27325922d6ab","slug":"cve-2026-106292","externalId":"CVE-2026-106292","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106292 — Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially …","description":"Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106292","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-122"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/524587778","type":"advisory","title":"Permissions Required"}],"epssScore":0.00332,"epssPercentile":0.24314,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:57.110Z","addedAt":"2026-10-06T20:39:31.367Z","updatedAt":"2026-10-07T14:39:33.023Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106292","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106292","note":"authoritative record"}]},{"id":"0351806d-5990-4462-9e27-8d1308ddb120","slug":"cve-2026-106247","externalId":"CVE-2026-106247","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106247 — Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially …","description":"Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106247","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-122"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://issues.chromium.org/issues/524435922"],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/524435922","type":"patch","title":"Patch"}],"epssScore":0.00332,"epssPercentile":0.24313,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:51.713Z","addedAt":"2026-10-06T20:39:31.001Z","updatedAt":"2026-10-07T14:39:32.739Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106247","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106247","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":1141,"totalPages":58,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:55:24.025Z","durationMs":34,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-122"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}