{"success":true,"data":{"threats":[{"id":"c5b3f807-3bcf-497d-afe2-f0f0027a018e","slug":"cve-2026-107503","externalId":"CVE-2026-107503","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107503 — Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explor…","description":"Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explorer in Eclipse Ditto Ditto Explorer [3.6.0,3.9.7] allows a craft link set an attacker-controlled OIDC authority with autoSso enabled. The UI then automatically starts a login at the genuine identity provider but exchanges the returned authorization code together with its PKCE code_verifier at an attacker-controlled token endpoint. This lets the attacker redeem the code for the victim's access and refresh tokens. Alternatively, an attacker-controlled api_uri causes the UI to send the victim's bearer token or Basic credentials to the attacker. Because the configuration is persisted, later visits to the UI without the crafted link repeat the token theft.","cveId":"CVE-2026-107503","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15","CWE-346","CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-ditto/ditto/security/advisories/GHSA-8767-g5qv-9jcf","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/380","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/1207","type":"advisory","title":"emo@eclipse.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:08.457Z","addedAt":"2026-10-08T10:39:34.980Z","updatedAt":"2026-10-08T21:05:47.863Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107503","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107503","note":"authoritative record"}]},{"id":"38d455d0-08a7-4825-9bc4-ab4865b69c09","slug":"cve-2026-94577","externalId":"CVE-2026-94577","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94577 — A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS vers…","description":"A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access Control (RBAC) validation checks. Successful exploitation allows an attacker to elevate privileges to root","cveId":"CVE-2026-94577","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39154","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00102,"epssPercentile":0.00862,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:06.113Z","addedAt":"2026-10-08T06:39:29.551Z","updatedAt":"2026-10-08T21:05:46.489Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94577","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94577","note":"authoritative record"}]},{"id":"2dc6063e-5634-4398-abe5-a0dc45797114","slug":"cve-2026-105294","externalId":"CVE-2026-105294","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105294 — Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the…","description":"Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.","cveId":"CVE-2026-105294","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Legcord/Legcord","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts#L296-L299","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Legcord/Legcord/blob/v1.3.0/src/main.ts#L277-L307","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Legcord/Legcord/issues/1163","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/legcord-1.1.0-through-1.3.0-chromium-switch-injection-via-settings-setconfig","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00189,"epssPercentile":0.07776,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T01:16:28.923Z","addedAt":"2026-10-05T01:50:40.091Z","updatedAt":"2026-10-06T17:50:41.954Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105294","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105294","note":"authoritative record"}]},{"id":"08e55fd7-af05-4dc1-a830-e0be837a0e82","slug":"cve-2026-103442","externalId":"CVE-2026-103442","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103442 — External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection.","description":"External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection.\n\nThis issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.","cveId":"CVE-2026-103442","cvssScore":7.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gerrit.wikimedia.org/r/q/I9c59e5c3f217c1eaa02934a076604049bac2b025","type":"advisory","title":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"},{"url":"https://phabricator.wikimedia.org/T435624","type":"advisory","title":"c4f26cc8-17ff-4c99-b5e2-38fc1793eacc"}],"epssScore":0.0028,"epssPercentile":0.18723,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:10.050Z","addedAt":"2026-09-30T17:50:47.789Z","updatedAt":"2026-09-30T17:50:47.789Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103442","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103442","note":"authoritative record"}]},{"id":"d97fd55d-ef4c-4d07-a73d-8689d71020e6","slug":"cve-2026-54918","externalId":"CVE-2026-54918","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54918 — NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox.","description":"NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author can change before the validation test harness runs. During pytest collection, tests/definitions_test.py passes the value to Repo.clone_from and create_remote(\"upstream\").fetch(), causing blind Git smart-HTTP requests to an attacker-selected host or loading attacker-controlled tests/known-*.json validation caches. The blind request cannot set arbitrary metadata-service headers or return response bodies, and this path does not execute remote Git hooks, but substituted known data can bypass slug, module, and rack uniqueness validation. This vulnerability is fixed in commit 8980c690097e92f5028c7e6df402b327d827ecd5.","cveId":"CVE-2026-54918","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15","CWE-829","CWE-918"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netbox-community/devicetype-library/commit/8980c690097e92f5028c7e6df402b327d827ecd5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netbox-community/devicetype-library/pull/4240","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-8cfp-3c4q-xr6x","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00415,"epssPercentile":0.33773,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T21:17:17.930Z","addedAt":"2026-09-17T21:50:37.999Z","updatedAt":"2026-09-30T17:50:44.624Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54918","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54918","note":"authoritative record"}]},{"id":"5213369a-c104-4f3b-9e17-cb6fb320af20","slug":"cve-2026-87987","externalId":"CVE-2026-87987","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87987 — An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignm…","description":"An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.","cveId":"CVE-2026-87987","cvssScore":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe5","type":"advisory","title":"6f8de1f0-f67e-45a6-b68f-98777fdb759c"}],"epssScore":0.00564,"epssPercentile":0.45117,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T15:17:07.793Z","addedAt":"2026-09-11T15:50:35.706Z","updatedAt":"2026-09-11T17:50:34.464Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87987","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87987","note":"authoritative record"}]},{"id":"63793313-f948-4275-a746-777620b33db7","slug":"cve-2026-85217","externalId":"CVE-2026-85217","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85217 — A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user not…","description":"A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.","cveId":"CVE-2026-85217","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.exe","type":"advisory","title":"psirt@autodesk.com"},{"url":"https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0016","type":"advisory","title":"psirt@autodesk.com"}],"epssScore":0.00187,"epssPercentile":0.07592,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T14:17:09.380Z","addedAt":"2026-09-10T15:50:37.750Z","updatedAt":"2026-09-11T05:50:34.559Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85217","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85217","note":"authoritative record"}]},{"id":"1cd5316f-6d23-4660-81fd-a5d3ff86d4f4","slug":"cve-2026-13745","externalId":"CVE-2026-13745","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-13745 — A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting t…","description":"A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.","cveId":"CVE-2026-13745","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-78","CWE-15","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/google-github-actions/run-gemini-cli/releases/tag/v0.1.22","type":"advisory","title":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"},{"url":"https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g","type":"advisory","title":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"},{"url":"https://github.com/google-gemini/gemini-cli/releases/tag/v0.39.1","type":"advisory","title":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"},{"url":"https://www.pwned.info/articles/homing-in-on-arbitrary-code-execution-within-gemini-cli/","type":"advisory","title":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"},{"url":"https://www.redguard.ch/blog/2026/06/03/advisory-google-gemini-cli/","type":"advisory","title":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"}],"epssScore":0.00375,"epssPercentile":0.29361,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T09:17:00.703Z","addedAt":"2026-09-10T09:50:33.452Z","updatedAt":"2026-09-23T11:50:37.333Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13745","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-13745","note":"authoritative record"}]},{"id":"077edb6b-fd27-4d6f-8320-36ca07572337","slug":"cve-2026-19593","externalId":"CVE-2026-19593","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace.","description":"OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.","cveId":"CVE-2026-19593","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://openai.com/codex","type":"advisory","title":"8f4f43ab-ba69-4d92-aa1d-d772184d6fb7"}],"epssScore":0.00366,"epssPercentile":0.28369,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-01T18:17:40.480Z","addedAt":"2026-09-01T19:50:32.223Z","updatedAt":"2026-09-02T19:50:34.523Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19593","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19593","note":"authoritative record"}]},{"id":"7ac963f6-c4bd-4cd5-b899-bf247e415207","slug":"cve-2026-19592","externalId":"CVE-2026-19592","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disa…","description":"OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an attacker-controlled filesystem-monitor helper, Git can execute that helper while Codex collects repository metadata. The helper runs outside Codex's command sandbox and without a user-approval prompt, allowing attacker-controlled code to run with the user's privileges. The code can read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the source repository's local .git/config; exploitation requires a repository delivered or copied with that configuration intact.","cveId":"CVE-2026-19592","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/openai/codex/pull/22652","type":"advisory","title":"8f4f43ab-ba69-4d92-aa1d-d772184d6fb7"}],"epssScore":0.00112,"epssPercentile":0.01274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-01T18:17:40.370Z","addedAt":"2026-09-01T19:50:32.219Z","updatedAt":"2026-09-02T17:50:31.712Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19592","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19592","note":"authoritative record"}]},{"id":"708c370b-f847-487f-b0c0-d709d6f39eaa","slug":"cve-2026-16708","externalId":"CVE-2026-16708","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16708 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.","description":"IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.","cveId":"CVE-2026-16708","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"ibm","product":"db2 mirror for i","affectedVersions":[">= 7.4, <= 7.6"],"cwes":["CWE-15"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7283359","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00244,"epssPercentile":0.14374,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-14T20:16:49.457Z","addedAt":"2026-08-14T21:50:26.420Z","updatedAt":"2026-08-26T15:50:30.422Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16708","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16708","note":"authoritative record"}]},{"id":"927127c4-8af1-4bb3-9551-7f7d0fec5ff9","slug":"cve-2026-19884","externalId":"CVE-2026-19884","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the fo…","description":"In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt.\n\n\n\nAs of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder.","cveId":"CVE-2026-19884","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-theia/theia/pull/16809","type":"advisory","title":"emo@eclipse.org"},{"url":"https://github.com/eclipse-theia/theia/pull/17098","type":"advisory","title":"emo@eclipse.org"},{"url":"https://github.com/eclipse-theia/theia/pull/17148","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/231","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/175","type":"advisory","title":"emo@eclipse.org"}],"epssScore":0.00193,"epssPercentile":0.08183,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-14T16:16:55.073Z","addedAt":"2026-08-14T17:50:27.972Z","updatedAt":"2026-08-18T15:50:30.297Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19884","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19884","note":"authoritative record"}]},{"id":"34dffcca-0cef-45e8-87e8-a522737f1cbb","slug":"cve-2026-73661","externalId":"CVE-2026-73661","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-73661 — FreePBX is an open source IP PBX.","description":"FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.","cveId":"CVE-2026-73661","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/FreePBX/framework/commit/0591581654bc269df05cbb7093645d6934d4d861","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/FreePBX/framework/commit/ea684be89abb393d1aff7f979d5fd751ff338dfd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/FreePBX/security-reporting/security/advisories/GHSA-f6hc-rqxg-ch86","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00602,"epssPercentile":0.47147,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-13T22:17:27.627Z","addedAt":"2026-08-13T23:50:27.355Z","updatedAt":"2026-09-18T21:50:36.565Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73661","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-73661","note":"authoritative record"}]},{"id":"f0f665eb-832f-4c12-92c4-af8ad8a16cc6","slug":"cve-2026-66065","externalId":"CVE-2026-66065","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66065 — Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior.","description":"Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.","cveId":"CVE-2026-66065","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"PyPI","product":"ouroboros-ai","affectedVersions":["pkg:pypi/ouroboros-ai < 0.42.1"],"cwes":["CWE-15","CWE-94"],"tags":["nvd","status:received","osv","osv:ghsa-jv2h-4p9v-wf5w","ecosystem:pypi","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Q00/ouroboros/releases/tag/v0.42.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-jv2h-4p9v-wf5w","type":"advisory","title":"OSV GHSA-jv2h-4p9v-wf5w"},{"url":"https://github.com/Q00/ouroboros","type":"vendor","title":"OSV package"}],"epssScore":0.0024,"epssPercentile":0.1391,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-03T21:16:41.193Z","addedAt":"2026-08-03T22:30:24.020Z","updatedAt":"2026-09-10T21:50:34.091Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66065","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66065","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JV2H-4P9V-WF5W"}]},{"id":"9911e3ea-0a7c-411f-a996-949137154129","slug":"cve-2026-56567","externalId":"CVE-2026-56567","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-56567 — HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities.","description":"HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.","cveId":"CVE-2026-56567","cvssScore":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":"hcltech","product":"icontrol","affectedVersions":["4.3.0"],"cwes":["CWE-15"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00141,"epssPercentile":0.02962,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-31T16:17:07.290Z","addedAt":"2026-07-31T17:33:43.703Z","updatedAt":"2026-08-06T15:50:29.881Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56567","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-56567","note":"authoritative record"}]},{"id":"83bc7164-9220-4be3-aadb-0570fd44b20e","slug":"cve-2026-0418","externalId":"CVE-2026-0418","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-0418 — Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network\nto tamper with the s…","description":"Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network\nto tamper with the system.","cveId":"CVE-2026-0418","cvssScore":4.3,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:L/U:Amber","severity":"medium","vendor":"netgear","product":"cbr750 firmware","affectedVersions":["< 4.6.14.4","< 1.1.7.128","< 1.0.3.28","< 1.1.7.6","< 1.0.11.112","< 1.0.10.86","< 4.6.14.3","< 6.3.7.5","< 1.0.7.66","< 1.0.0.68"],"cwes":["CWE-15","CWE-610"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.netgear.com/support/product/cbr750/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/ex6120/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/ex6130/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/mr60/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/mr70/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/mr80/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/ms60/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/ms70/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/ms80/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax15/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax20/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax200/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax35v2/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax38v2/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax40v2/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax42/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax43/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax45/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax48/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax50/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax50s/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax75/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rax80/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/raxe450/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/raxe500/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbr750/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbr840/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbr850/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbre960/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbs750/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbs840/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbs850/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rbse960/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/rs700/","type":"advisory","title":"Product"},{"url":"https://www.netgear.com/support/product/xr1000/","type":"advisory","title":"Product"}],"epssScore":0.00245,"epssPercentile":0.14385,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-09T17:16:59.687Z","addedAt":"2026-07-28T20:12:20.279Z","updatedAt":"2026-07-28T20:12:20.279Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0418","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-0418","note":"authoritative record"}]},{"id":"8b0211e6-bd42-4556-88a4-fcef7a110948","slug":"cve-2026-1784","externalId":"CVE-2026-1784","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-1784 — The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy.","description":"The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.","cveId":"CVE-2026-1784","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"redhat","product":"openshift container platform","affectedVersions":["4.0"],"cwes":["CWE-15"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:23241","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23246","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25045","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25182","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25194","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26543","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28893","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28964","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-1784","type":"vendor","title":"Vendor Advisory"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2436075","type":"vendor","title":"Issue Tracking"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1784.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:70647","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00194,"epssPercentile":0.08302,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-02T09:16:15.683Z","addedAt":"2026-07-28T20:12:13.907Z","updatedAt":"2026-10-01T17:50:41.590Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1784","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-1784","note":"authoritative record"}]},{"id":"42f91dac-d0f6-4339-b609-f23d33b4f377","slug":"cve-2019-25716","externalId":"CVE-2019-25716","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2019-25716 — Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the mon…","description":"Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.","cveId":"CVE-2019-25716","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"draeger","product":"infinity delta firmware","affectedVersions":[],"cwes":["CWE-15"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vf10-1-security-advisory.pdf","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitor-dos-via-malformed-network-packet","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00413,"epssPercentile":0.33587,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-01T22:16:17.170Z","addedAt":"2026-07-28T20:12:13.238Z","updatedAt":"2026-07-28T20:12:13.238Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-25716","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2019-25716","note":"authoritative record"}]},{"id":"6d769cdf-1248-433d-8dfb-b6bab386a315","slug":"cve-2026-44417","externalId":"CVE-2026-44417","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44417 — The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might l…","description":"The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. \nUsers are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.","cveId":"CVE-2026-44417","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"apache","product":"cxf","affectedVersions":["< 3.6.11",">= 4.0.0, < 4.1.6","4.2.0"],"cwes":["CWE-20","CWE-15"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/bqg6gjy2cx7rfyqjxcpv3jwjvmclvz4o","type":"vendor","title":"Mailing List"},{"url":"https://access.redhat.com/errata/RHSA-2026:37390","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-44417","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480729","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44417.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epssScore":0.00903,"epssPercentile":0.58533,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-22T13:16:22.600Z","addedAt":"2026-07-28T20:12:08.729Z","updatedAt":"2026-07-28T20:12:08.729Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44417","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44417","note":"authoritative record"}]},{"id":"d339f647-ff9d-4cac-972b-b7df90d501bb","slug":"cve-2026-30817","externalId":"CVE-2026-30817","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-30817 — An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitr…","description":"An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.","cveId":"CVE-2026-30817","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"tp-link","product":"archer ax53 firmware","affectedVersions":["< 1.7.1","1.0"],"cwes":["CWE-15","CWE-610"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","type":"advisory","title":"Product"},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","type":"advisory","title":"Product"},{"url":"https://www.tp-link.com/us/support/faq/5055/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2305","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00361,"epssPercentile":0.27816,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-04-08T19:25:20.627Z","addedAt":"2026-07-28T20:12:02.890Z","updatedAt":"2026-07-28T20:12:02.890Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30817","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-30817","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":25,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T03:16:21.777Z","durationMs":50,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-15"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}