{"success":true,"data":{"threats":[{"id":"9608bf8a-c014-4ce1-a795-a631a0e1aa6e","slug":"cve-2026-107324","externalId":"CVE-2026-107324","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107324 — An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a ma…","description":"An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.","cveId":"CVE-2026-107324","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/GODRIVER-4102","type":"advisory","title":"cna@mongodb.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.020Z","addedAt":"2026-10-08T19:33:16.911Z","updatedAt":"2026-10-08T21:05:52.328Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107324","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107324","note":"authoritative record"}]},{"id":"15a97eb9-b645-4a03-a247-3af7aa66788b","slug":"cve-2026-105398","externalId":"CVE-2026-105398","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105398 — ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call t…","description":"ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through crafted input to crash the server, causing a denial of service.","cveId":"CVE-2026-105398","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jvjm-9f73-fhpq","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-heap-buffer-overflow-via-getvirtualpixels-api","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:32.787Z","addedAt":"2026-10-08T16:39:35.591Z","updatedAt":"2026-10-08T21:05:49.644Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105398","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105398","note":"authoritative record"}]},{"id":"100ca340-5353-4bc7-9e7a-7156cfc8b025","slug":"cve-2026-107446","externalId":"CVE-2026-107446","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107446 — containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_b…","description":"containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.","cveId":"CVE-2026-107446","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/image_file.cpp","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/overlaybd/lsmt/file.cpp","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/containerd/overlaybd/commit/a536e3341c82517268b5ce32375b36faecb1fb40","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/containerd/overlaybd/commit/d80c1790920a17e84da025675530624aee753f1b","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/containerd/overlaybd/pull/438","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00407,"epssPercentile":0.32887,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:19.410Z","addedAt":"2026-10-08T04:39:33.019Z","updatedAt":"2026-10-08T23:06:37.100Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107446","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107446","note":"authoritative record"}]},{"id":"a6d8e418-82b2-46e1-8c6f-b16cfa4ae3ed","slug":"cve-2026-107224","externalId":"CVE-2026-107224","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.","cveId":"CVE-2026-107224","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.1.0, < 2.11.1-0.20260805032953-db93f8d89de7"],"cwes":["CWE-190","CWE-681"],"tags":["nvd","status:received","osv","osv:ghsa-fw94-4wwp-w8pw","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/db93f8d89de71589069a54d1b998af02e3c5f7cd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2369","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-fw94-4wwp-w8pw","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-fw94-4wwp-w8pw","type":"advisory","title":"OSV GHSA-fw94-4wwp-w8pw"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00356,"epssPercentile":0.2731,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:35.140Z","addedAt":"2026-10-07T20:39:40.439Z","updatedAt":"2026-10-08T21:05:43.717Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107224","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107224","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-FW94-4WWP-W8PW"}]},{"id":"8a2bd89f-517c-4cd3-8e90-391e6dfc0b4d","slug":"cve-2026-107217","externalId":"CVE-2026-107217","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107217 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.","cveId":"CVE-2026-107217","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.0.0, < 2.11.1-0.20260910071107-696050fbf14e","pkg:golang/github.com/xuri/excelize >= 1.1.0, <= 1.4.1"],"cwes":["CWE-129","CWE-190"],"tags":["nvd","status:received","osv","osv:ghsa-c85p-xxjj-2r75","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/696050fbf14e74e96a58eef2b16aaf72f381a6a8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2394","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-c85p-xxjj-2r75","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-c85p-xxjj-2r75","type":"advisory","title":"OSV GHSA-c85p-xxjj-2r75"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00335,"epssPercentile":0.24787,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:33.957Z","addedAt":"2026-10-07T20:39:40.386Z","updatedAt":"2026-10-08T21:05:43.486Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107217","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107217","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C85P-XXJJ-2R75"}]},{"id":"dcc5b659-c82b-4a19-a4fe-d3a3093a1d4a","slug":"cve-2026-106574","externalId":"CVE-2026-106574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106574 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31.","cveId":"CVE-2026-106574","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122","CWE-125","CWE-131","CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00201,"epssPercentile":0.09186,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:43.467Z","addedAt":"2026-10-07T16:39:32.614Z","updatedAt":"2026-10-08T21:05:42.126Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106574","note":"authoritative record"}]},{"id":"aaa4f703-97ec-4879-a77d-7803e14317be","slug":"cve-2026-106571","externalId":"CVE-2026-106571","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106571 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels API can trigger an integer calculation error and write beyond a heap buffer, crashing the server process. This issue is fixed in versions 6.9.13-56 and 7.1.2-31.","cveId":"CVE-2026-106571","cvssScore":5.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190","CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/8f3a15e60b723bfe3e80bd1b5e4bee88397467f7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jvjm-9f73-fhpq","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/91f4ed74a1fd8326ade11a1153de110f22d89aa1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0013,"epssPercentile":0.02276,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:42.863Z","addedAt":"2026-10-07T16:39:32.592Z","updatedAt":"2026-10-08T21:05:42.040Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106571","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106571","note":"authoritative record"}]},{"id":"e4d17d5d-5b60-493f-ac11-1cb50b4af4df","slug":"cve-2026-59346","externalId":"CVE-2026-59346","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-59346 — VMware Workstation and Fusion contain an integer-overflow vulnerability.","description":"VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.\n\nAffected versions:\n- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)\n- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)","cveId":"CVE-2026-59346","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/security-advisories/0/38288","type":"advisory","title":"security@vmware.com"}],"epssScore":0.00258,"epssPercentile":0.16019,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T06:16:35.543Z","addedAt":"2026-10-07T06:39:29.008Z","updatedAt":"2026-10-07T16:39:31.709Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59346","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-59346","note":"authoritative record"}]},{"id":"aa76b508-e094-4ef6-bc8f-6e9212cd44cb","slug":"cve-2026-106417","externalId":"CVE-2026-106417","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106417 — Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandb…","description":"Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106417","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-190"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/536471438","type":"advisory","title":"Permissions Required"}],"epssScore":0.00338,"epssPercentile":0.25144,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:11.433Z","addedAt":"2026-10-06T20:39:32.333Z","updatedAt":"2026-10-07T14:39:33.676Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106417","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106417","note":"authoritative record"}]},{"id":"f81b4884-6cee-451f-9bf4-1815e67166dd","slug":"cve-2026-106332","externalId":"CVE-2026-106332","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106332 — Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page.","description":"Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106332","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-190"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/553454734","type":"advisory","title":"Permissions Required"}],"epssScore":0.00214,"epssPercentile":0.1078,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:01.583Z","addedAt":"2026-10-06T20:39:31.678Z","updatedAt":"2026-10-07T14:39:33.296Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106332","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106332","note":"authoritative record"}]},{"id":"3de7d63f-10a4-48a0-873c-e637a5a50854","slug":"cve-2026-106239","externalId":"CVE-2026-106239","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106239 — Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code out…","description":"Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106239","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-190"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/546630009","type":"advisory","title":"Permissions Required"}],"epssScore":0.00423,"epssPercentile":0.34646,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:50.800Z","addedAt":"2026-10-06T20:39:30.934Z","updatedAt":"2026-10-07T14:39:32.655Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106239","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106239","note":"authoritative record"}]},{"id":"e7cf92c5-c0e1-4924-97a7-1883c44a7a22","slug":"cve-2026-105839","externalId":"CVE-2026-105839","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105839 — libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via c…","description":"libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.","cveId":"CVE-2026-105839","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sezero/mikmod","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/blob/libmikmod-3.3.13/libmikmod/loaders/load_okt.c#L286","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/blob/libmikmod-3.3.14/libmikmod/NEWS","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/commit/097b69281fad6ba38a553569e6f55dbfdd71dc2a","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/libmikmod-before-3.3.14-heap-buffer-overflow-via-okt-loader-okt-dopbod","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00146,"epssPercentile":0.0334,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:41.133Z","addedAt":"2026-10-06T15:51:00.259Z","updatedAt":"2026-10-06T17:50:42.360Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105839","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105839","note":"authoritative record"}]},{"id":"5b4f68b1-8adf-44ed-a082-58962bb8ab44","slug":"cve-2026-105837","externalId":"CVE-2026-105837","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105837 — libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflo…","description":"libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential code execution.","cveId":"CVE-2026-105837","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sezero/mikmod","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/blob/libmikmod-3.3.13/libmikmod/loaders/load_dsm.c#L273","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/blob/libmikmod-3.3.14/libmikmod/NEWS","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/sezero/mikmod/commit/a125eabbd086f311496ae46d08aaebcad0a1c426","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/libmikmod-before-3.3.14-heap-buffer-overflow-via-dsm-loader-integer-overflow","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00148,"epssPercentile":0.03506,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:40.763Z","addedAt":"2026-10-06T15:51:00.247Z","updatedAt":"2026-10-06T20:39:29.662Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105837","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105837","note":"authoritative record"}]},{"id":"182fe095-1fdf-470a-bbbf-e7bd82959731","slug":"cve-2026-75820","externalId":"CVE-2026-75820","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75820 — GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp.","description":"GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.\n\n\n\nThis issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.","cveId":"CVE-2026-75820","cvssScore":1.8,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://aspell.net/","type":"advisory","title":"cvd@cert.pl"},{"url":"https://cert.pl/en/posts/2026/10/CVE-2026-75818","type":"advisory","title":"cvd@cert.pl"}],"epssScore":0.00125,"epssPercentile":0.01977,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T11:17:30.020Z","addedAt":"2026-10-06T11:50:42.443Z","updatedAt":"2026-10-06T15:51:00.201Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75820","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75820","note":"authoritative record"}]},{"id":"610fa5b9-9c17-4b7a-962b-754137e192c5","slug":"cve-2026-49885","externalId":"CVE-2026-49885","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-49885 — In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow.","description":"In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-49885","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0","17.0"],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00073,"epssPercentile":0.00061,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:20.873Z","addedAt":"2026-10-05T19:50:42.890Z","updatedAt":"2026-10-07T14:39:32.588Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49885","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-49885","note":"authoritative record"}]},{"id":"9fed1f11-c109-4f1c-b5b3-e26b6320920b","slug":"cve-2026-20533","externalId":"CVE-2026-20533","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20533 — In display, there is a possible escalation of privilege due to an integer overflow.","description":"In display, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11296678; Issue ID: MSV-9167.","cveId":"CVE-2026-20533","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/October-2026","type":"advisory","title":"security@mediatek.com"}],"epssScore":0.00109,"epssPercentile":0.0114,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T02:16:52.150Z","addedAt":"2026-10-05T03:50:40.236Z","updatedAt":"2026-10-06T15:50:56.931Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20533","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20533","note":"authoritative record"}]},{"id":"bf320b6d-c149-4c63-b1d7-f572dec7d6ce","slug":"cve-2026-79113","externalId":"CVE-2026-79113","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79113 — OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.","description":"OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.","cveId":"CVE-2026-79113","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-190"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aswf.io/","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/AcademySoftwareFoundation/openapv/commit/b5cc54bc786040ba3ac54020e7320e0add51e107","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/AcademySoftwareFoundation/openapv/compare/v0.3.0.0...v1.1.1.0","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/AcademySoftwareFoundation/openapv/issues/219","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/AcademySoftwareFoundation/openapv/pull/226","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/AcademySoftwareFoundation/openapv/tree/kp_handling_issues_20260713","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.0014,"epssPercentile":0.02844,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T01:17:25.287Z","addedAt":"2026-10-03T03:50:40.217Z","updatedAt":"2026-10-06T17:50:41.826Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79113","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79113","note":"authoritative record"}]},{"id":"b2b5b6cf-2dbe-4236-b4d0-982986e92de5","slug":"cve-2026-103629","externalId":"CVE-2026-103629","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103629 — Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page.","description":"Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-103629","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 154.0.8037.97"],"cwes":["CWE-190"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/562038679","type":"advisory","title":"Permissions Required"}],"epssScore":0.00201,"epssPercentile":0.09163,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T16:16:44.043Z","addedAt":"2026-10-02T17:50:40.587Z","updatedAt":"2026-10-05T15:50:46.516Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103629","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103629","note":"authoritative record"}]},{"id":"dbbf64c6-c0ab-4399-bba7-f81f0dc0685a","slug":"cve-2026-103621","externalId":"CVE-2026-103621","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103621 — Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page.","description":"Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-103621","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 154.0.8037.97"],"cwes":["CWE-190"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/556268833","type":"advisory","title":"Permissions Required"}],"epssScore":0.00202,"epssPercentile":0.09197,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T16:16:43.180Z","addedAt":"2026-10-02T17:50:40.548Z","updatedAt":"2026-10-05T15:50:46.477Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103621","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103621","note":"authoritative record"}]},{"id":"db6025d8-4cd6-4187-b045-7948db042211","slug":"cve-2026-83632","externalId":"CVE-2026-83632","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83632 — Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.","description":"Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-83632","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-122","CWE-190","CWE-770"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/zjv6hjmhl4tb4l4l1dk4bmc2whxh0lb4","type":"advisory","title":"security@apache.org"}],"epssScore":0.00378,"epssPercentile":0.29631,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:58.647Z","addedAt":"2026-10-02T13:50:40.958Z","updatedAt":"2026-10-02T17:50:40.479Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83632","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83632","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":612,"totalPages":31,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:25:39.255Z","durationMs":25,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-190"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}