{"success":true,"data":{"threats":[{"id":"dcc5b659-c82b-4a19-a4fe-d3a3093a1d4a","slug":"cve-2026-106574","externalId":"CVE-2026-106574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106574 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31.","cveId":"CVE-2026-106574","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122","CWE-125","CWE-131","CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00201,"epssPercentile":0.09186,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:43.467Z","addedAt":"2026-10-07T16:39:32.614Z","updatedAt":"2026-10-08T21:05:42.126Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106574","note":"authoritative record"}]},{"id":"57621681-e911-4e04-93e9-bdbc5d563bc1","slug":"cve-2026-104424","externalId":"CVE-2026-104424","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104424 — Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count s…","description":"Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.","cveId":"CVE-2026-104424","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-95m2-vx53-v2jw","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zebra-before-6.1.0-incorrect-block-size-calculation-in-getblocktemplate","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00273,"epssPercentile":0.18057,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:12.580Z","addedAt":"2026-10-02T13:50:40.454Z","updatedAt":"2026-10-06T03:50:41.657Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104424","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104424","note":"authoritative record"}]},{"id":"51ff1969-b9e0-4545-9494-c0a2021c2d5d","slug":"cve-2026-102505","externalId":"CVE-2026-102505","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102505 — Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.","description":"Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.\n\nFor a paletted image, getsamples() with type \"float\" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.\n\nAn attacker-supplied image controls the overflowing bytes through its palette.","cveId":"CVE-2026-102505","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","severity":"medium","vendor":"tonycoz","product":"imager","affectedVersions":["< 1.037"],"cwes":["CWE-131"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db.patch"],"references":[{"url":"https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db.patch","type":"patch","title":"Patch"},{"url":"https://github.com/tonycoz/imager/security/advisories/GHSA-4rx6-cgv3-fmxp","type":"vendor","title":"Mitigation"},{"url":"https://metacpan.org/release/TONYC/Imager-1.037/changes","type":"advisory","title":"Release Notes"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/10","type":"advisory","title":"Mailing List"}],"epssScore":0.00241,"epssPercentile":0.14052,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T14:17:20.237Z","addedAt":"2026-10-01T15:50:41.731Z","updatedAt":"2026-10-08T14:40:01.332Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102505","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102505","note":"authoritative record"}]},{"id":"4f968c39-ce37-4066-b921-9301a3a95a89","slug":"cve-2026-47578","externalId":"CVE-2026-47578","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47578 — NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calc…","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47578","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47578","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47578","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00136,"epssPercentile":0.02618,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:27.130Z","addedAt":"2026-09-30T17:50:48.244Z","updatedAt":"2026-10-01T05:50:42.948Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47578","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47578","note":"authoritative record"}]},{"id":"547bf893-694f-4573-ad09-a6d249c62552","slug":"cve-2026-102729","externalId":"CVE-2026-102729","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102729 — `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id.","description":"`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.","cveId":"CVE-2026-102729","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131","CWE-787"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-threadx/guix/security/advisories/GHSA-372w-c338-xj8p","type":"advisory","title":"emo@eclipse.org"}],"epssScore":0.00117,"epssPercentile":0.01543,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T18:17:12.620Z","addedAt":"2026-09-29T19:50:41.579Z","updatedAt":"2026-09-29T19:50:41.579Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102729","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102729","note":"authoritative record"}]},{"id":"6d9b2218-0a31-4b56-b785-ae98a0523819","slug":"cve-2026-95509","externalId":"CVE-2026-95509","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95509 — Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causin…","description":"Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.","cveId":"CVE-2026-95509","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-131"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-95509:","type":"advisory","title":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"}],"epssScore":0.00312,"epssPercentile":0.22036,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T11:16:43.947Z","addedAt":"2026-09-29T11:50:40.546Z","updatedAt":"2026-09-30T17:50:45.777Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95509","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95509","note":"authoritative record"}]},{"id":"d19dd4f9-01d3-49b9-9a56-6ca019843265","slug":"cve-2026-88355","externalId":"CVE-2026-88355","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88355 — An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr().","description":"An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.","cveId":"CVE-2026-88355","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/codeplea/tinyexpr/issues/145","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/szaydel/tinyexpr/commit/fe7459728c2ab8d2f91365abe56601cdd0e24f9b","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00343,"epssPercentile":0.25784,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T16:17:12.833Z","addedAt":"2026-09-24T17:50:39.517Z","updatedAt":"2026-10-06T18:39:26.311Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88355","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88355","note":"authoritative record"}]},{"id":"b3e8c5dc-32cd-48bf-8837-47be6d27774e","slug":"cve-2026-13466","externalId":"CVE-2026-13466","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-13466 — Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers.","description":"Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers.\n\nThis issue affects Trusted Firmware: through socfpga_v2.14.0.","cveId":"CVE-2026-13466","cvssScore":8.3,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.altera.com/product-security/advisory/asa-0006","type":"advisory","title":"04c0172e-9735-4a9d-a92a-fe01fa863447"}],"epssScore":0.00109,"epssPercentile":0.01128,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T15:17:19.280Z","addedAt":"2026-09-24T15:50:40.182Z","updatedAt":"2026-09-24T19:50:38.892Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13466","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-13466","note":"authoritative record"}]},{"id":"5c28e116-5140-44cc-8a63-e4494eb1fded","slug":"cve-2026-88830","externalId":"CVE-2026-88830","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88830 — A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted C…","description":"A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.","cveId":"CVE-2026-88830","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-88830","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531344","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00351,"epssPercentile":0.26657,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T17:17:18.427Z","addedAt":"2026-09-23T17:50:39.940Z","updatedAt":"2026-09-23T21:50:38.154Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88830","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88830","note":"authoritative record"}]},{"id":"6b271dd2-afd3-40da-99a5-74b3d299e32b","slug":"cve-2026-84448","externalId":"CVE-2026-84448","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84448 — libheif is a HEIF and AVIF file format decoder and encoder.","description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and height. A later heif_region_get_mask_image() call derives the read length from the region geometry, so an undersized stored buffer causes heif_region_get_inline_mask_image() to read beyond the heap allocation and copy adjacent bytes into the returned monochrome mask image. This can disclose heap data or crash an application that constructs region metadata through the writer API, while the file-parsing path is not affected because it validates the canonical mask size. This issue is fixed in version 1.23.2.","cveId":"CVE-2026-84448","cvssScore":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-131"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/strukturag/libheif/commit/646d85fbf5bd18fc3cdc516e915e59072de2d510","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strukturag/libheif/releases/tag/v1.23.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strukturag/libheif/security/advisories/GHSA-p58j-h3vm-3fp5","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00186,"epssPercentile":0.07516,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T16:17:12.840Z","addedAt":"2026-09-18T17:50:37.010Z","updatedAt":"2026-09-24T21:50:42.837Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84448","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84448","note":"authoritative record"}]},{"id":"55a2e944-79d9-444c-bcda-9ea6e9551ba6","slug":"cve-2026-67549","externalId":"CVE-2026-67549","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67549 — OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation.","description":"OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer. tiffinput::read_native_scanline_locked() nevertheless invokes tiffinput::bit_convert() with 8-bit output and writes one expanded byte per value into that smaller buffer, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/tiff.imageio/tiffinput.cpp, TIFFInput::bit_convert(), TIFFInput::read_native_scanline_locked(), PHOTOMETRIC_SEPARATED, 1-bit CMYK, and native uint1 ImageSpec, which define the relevant source path, functions, state, and trigger. This issue is fixed in 3.1.16.0.","cveId":"CVE-2026-67549","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","severity":"high","vendor":"openimageio","product":"openimageio","affectedVersions":["< 3.1.16.0"],"cwes":["CWE-122","CWE-131","CWE-787"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/6e9b86ee4cce8fd7bed6cfb101a266d8f8a296d4","https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5296"],"references":[{"url":"https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/6e9b86ee4cce8fd7bed6cfb101a266d8f8a296d4","type":"patch","title":"Patch"},{"url":"https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5296","type":"patch","title":"Issue Tracking"},{"url":"https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.1.16.0","type":"advisory","title":"Release Notes"},{"url":"https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3wxw-rqhw-j2w4","type":"vendor","title":"Exploit"},{"url":"https://github.com/user-attachments/files/29615314/poc.zip","type":"advisory","title":"Exploit"}],"epssScore":0.00288,"epssPercentile":0.19594,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T16:17:08.733Z","addedAt":"2026-09-18T17:50:36.903Z","updatedAt":"2026-09-29T19:50:40.324Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67549","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67549","note":"authoritative record"}]},{"id":"1568b679-2cc1-4221-a877-8776d6d9e8e1","slug":"cve-2026-54692","externalId":"CVE-2026-54692","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54692 — SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles.","description":"SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat decode loop to write two file-controlled bytes per literal. When ceil(width/8) produces an odd row stride, the X10 literal count includes a padding byte for every row, but the destination has no space for those bytes, so loading the XBM through sail_load_from_file, sail_load_from_memory, or sail_start_loading_* produces a forward heap overwrite that scales with image height. The X11 static char path is not affected. The overwrite can corrupt process state, cause reliable crashes, and potentially enable code execution in a susceptible consuming application. This issue is fixed in version 1.0.0.","cveId":"CVE-2026-54692","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131","CWE-787"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/HappySeaFox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/HappySeaFox/sail/releases/tag/v1.0.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/HappySeaFox/sail/security/advisories/GHSA-gp27-qv2x-55v5","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00194,"epssPercentile":0.08322,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T20:16:52.550Z","addedAt":"2026-09-17T21:50:37.830Z","updatedAt":"2026-09-24T21:50:42.584Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54692","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54692","note":"authoritative record"}]},{"id":"6e70905d-a420-4d62-ae4f-a322d64863ef","slug":"cve-2026-91962","externalId":"CVE-2026-91962","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91962 — FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages.","description":"FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.","cveId":"CVE-2026-91962","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"freerdp","product":"freerdp","affectedVersions":["< 3.31.0"],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f5p6-88mh-59vg","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-integer-overflow-via-audin-apple-backends","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00261,"epssPercentile":0.16453,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T16:17:51.763Z","addedAt":"2026-09-15T17:50:37.305Z","updatedAt":"2026-09-23T21:50:37.706Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91962","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91962","note":"authoritative record"}]},{"id":"a1af87a6-fc5e-4c64-871a-84432155ef2b","slug":"cve-2026-47773","externalId":"CVE-2026-47773","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47773 — ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models.","description":"ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.","cveId":"CVE-2026-47773","cvssScore":7.2,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131","CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/arduino-libraries/ArduinoBLE/pull/431/changes/1460e1a68221fca854b7b1e278cab76e763c00e6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/arduino-libraries/ArduinoBLE/releases/tag/2.0.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/arduino-libraries/ArduinoBLE/security/advisories/GHSA-77v6-cw9f-9whg","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0015,"epssPercentile":0.03674,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T21:17:09.940Z","addedAt":"2026-09-11T21:50:39.041Z","updatedAt":"2026-09-30T19:50:40.966Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47773","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47773","note":"authoritative record"}]},{"id":"e7464cb1-3af3-4234-ba05-31db7d4871e3","slug":"cve-2026-22590","externalId":"CVE-2026-22590","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-22590 — eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group).","description":"eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST-fragment path, Fast-DDS computes `incoming_length` based on `sampleSize` and calls `memcpy()` without validating `incoming_data.length >= incoming_length`. As a result, `CacheChange_t::add_fragments()` reads past the received UDP datagram buffer and into adjacent heap memory, copying those bytes into the reassembly buffer. In a Discovery Server deployment, the resulting `CacheChange_t` can be relayed to other participants, meaning that a newly joining participant may receive leaked heap memory (e.g., pointer values that could aid ASLR bypass). Versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 fix the issue.","cveId":"CVE-2026-22590","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r7h-hwfj-q626","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00383,"epssPercentile":0.3025,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T16:17:02.387Z","addedAt":"2026-09-09T17:50:39.285Z","updatedAt":"2026-09-09T21:50:42.728Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22590","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-22590","note":"authoritative record"}]},{"id":"7fb74466-88d1-4ad4-97d7-83a701faf449","slug":"cve-2026-69598","externalId":"CVE-2026-69598","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69598 — Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.","description":"Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.","cveId":"CVE-2026-69598","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","r2","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-131"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69598"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69598","type":"patch","title":"Patch"}],"epssScore":0.00819,"epssPercentile":0.55891,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:19:30.363Z","addedAt":"2026-09-08T19:50:40.489Z","updatedAt":"2026-09-24T23:50:39.718Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69598","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69598","note":"authoritative record"}]},{"id":"46a4fd83-ac2e-4427-bc76-711b82254483","slug":"cve-2026-78221","externalId":"CVE-2026-78221","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78221 — An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cau…","description":"An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.","cveId":"CVE-2026-78221","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://community.openvpn.net/Security%20Announcements/CVE-2026-78221","type":"advisory","title":"security@openvpn.net"}],"epssScore":0.00116,"epssPercentile":0.01488,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-07T08:17:12.813Z","addedAt":"2026-09-07T09:50:33.003Z","updatedAt":"2026-09-08T19:50:37.348Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78221","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78221","note":"authoritative record"}]},{"id":"3c89c26d-c0a3-4c03-ac30-43d8549ec373","slug":"cve-2026-18743","externalId":"CVE-2026-18743","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18743 — A flaw was found in popt.","description":"A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).","cveId":"CVE-2026-18743","cvssScore":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-18743","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510809","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:56984","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00141,"epssPercentile":0.0296,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-01T02:16:57.647Z","addedAt":"2026-09-01T03:50:30.945Z","updatedAt":"2026-09-08T23:50:33.004Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18743","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18743","note":"authoritative record"}]},{"id":"3a484110-0e7f-41b9-a062-d27a6461f37c","slug":"cve-2026-78002","externalId":"CVE-2026-78002","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78002 — A flaw was found in rsyslog.","description":"A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.","cveId":"CVE-2026-78002","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-78002","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2521135","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3","type":"advisory","title":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/29/1","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2026:69541","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69540","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71603","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00707,"epssPercentile":0.52001,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T17:20:29.367Z","addedAt":"2026-08-27T17:50:35.745Z","updatedAt":"2026-09-25T15:50:38.023Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78002","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78002","note":"authoritative record"}]},{"id":"e382442e-b701-4425-be7b-e83ece98fae5","slug":"cve-2026-16924","externalId":"CVE-2026-16924","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16924 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory…","description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.","cveId":"CVE-2026-16924","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"ibm","product":"vios","affectedVersions":[">= 4.1.0, < 4.1.0.50",">= 4.1.1.0, < 4.1.1.30",">= 4.1.2.0, < 4.1.2.20",">= 7.2.5, <= 7.2.5.212",">= 7.3.2, <= 7.3.2.5",">= 7.3.3, <= 7.3.3.2",">= 7.3.4, <= 7.3.4.1"],"cwes":["CWE-191","CWE-131"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://www.ibm.com/support/pages/node/7283858"],"references":[{"url":"https://www.ibm.com/support/pages/node/7283858","type":"patch","title":"Patch"}],"epssScore":0.00549,"epssPercentile":0.44191,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T15:17:28.607Z","addedAt":"2026-08-20T15:50:28.562Z","updatedAt":"2026-08-24T21:50:29.096Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16924","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16924","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":57,"totalPages":3,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:55:17.678Z","durationMs":23,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-131"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}