{"success":true,"data":{"threats":[{"id":"581b817f-0aab-4049-9aad-1cfedcd7a0f8","slug":"cve-2026-105823","externalId":"CVE-2026-105823","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105823 — ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be …","description":"ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data.","cveId":"CVE-2026-105823","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-cut-encoder","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:34.140Z","addedAt":"2026-10-08T16:39:35.650Z","updatedAt":"2026-10-08T21:05:49.886Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105823","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105823","note":"authoritative record"}]},{"id":"ba5e1a18-54bb-4a96-a783-f43d712867a7","slug":"cve-2026-107510","externalId":"CVE-2026-107510","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107510 — An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","description":"An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","cveId":"CVE-2026-107510","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88","CWE-269","CWE-284"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.infoblox.com/s/article/Security-Advisory-NIOS-Maintenance-Mode-Permits-Root-Shell","type":"advisory","title":"f84ca5ce-fbe7-4668-8724-994599108a02"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:09.553Z","addedAt":"2026-10-08T10:39:34.992Z","updatedAt":"2026-10-08T23:06:37.387Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107510","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107510","note":"authoritative record"}]},{"id":"8d6f5986-d6e5-420f-b1fd-7490862bf16f","slug":"cve-2026-76281","externalId":"CVE-2026-76281","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76281 — Improper Access Control.","description":"Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.","cveId":"CVE-2026-76281","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1002","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00147,"epssPercentile":0.03385,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:19.483Z","addedAt":"2026-10-07T22:39:36.701Z","updatedAt":"2026-10-08T21:05:44.698Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76281","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76281","note":"authoritative record"}]},{"id":"59ea91b0-63ef-404e-8140-827a296a69b6","slug":"cve-2026-76265","externalId":"CVE-2026-76265","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76265 — In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a us…","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.","cveId":"CVE-2026-76265","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00234,"epssPercentile":0.13173,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:17.150Z","addedAt":"2026-10-07T22:39:36.579Z","updatedAt":"2026-10-08T21:05:44.105Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76265","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76265","note":"authoritative record"}]},{"id":"27d87035-fa11-475c-b0ac-114c5b2f2f29","slug":"cve-2026-76498","externalId":"CVE-2026-76498","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76498 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engi…","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76498 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.","cveId":"CVE-2026-76498","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-apic-UOXWtfh","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.003,"epssPercentile":0.20853,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:01.670Z","addedAt":"2026-10-07T18:39:31.558Z","updatedAt":"2026-10-08T21:05:43.118Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76498","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76498","note":"authoritative record"}]},{"id":"b11918c9-cce2-400f-882e-a6d8f4f43f71","slug":"cve-2026-76463","externalId":"CVE-2026-76463","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76463 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensiv…","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","cveId":"CVE-2026-76463","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00139,"epssPercentile":0.0282,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:58.833Z","addedAt":"2026-10-07T18:39:31.431Z","updatedAt":"2026-10-08T21:05:42.773Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76463","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76463","note":"authoritative record"}]},{"id":"9fa5111b-b757-4b19-98eb-23278916892d","slug":"cve-2026-76455","externalId":"CVE-2026-76455","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76455 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive int…","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","cveId":"CVE-2026-76455","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00284,"epssPercentile":0.19166,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:57.520Z","addedAt":"2026-10-07T18:39:31.391Z","updatedAt":"2026-10-08T21:05:42.643Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76455","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76455","note":"authoritative record"}]},{"id":"533e7f82-5a07-4afc-8bae-336176169821","slug":"cve-2026-20038","externalId":"CVE-2026-20038","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20038 — A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenti…","description":"A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts.\r\n\r\nThis vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to&nbsp;DHCP traffic through an affected device. A successful exploit could allow the attacker to bypass EPG contracts on the affected device.","cveId":"CVE-2026-20038","cvssScore":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-epgcbp-SfDU7NLf","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00301,"epssPercentile":0.20954,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:54.690Z","addedAt":"2026-10-07T18:39:31.291Z","updatedAt":"2026-10-08T21:05:42.408Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20038","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20038","note":"authoritative record"}]},{"id":"02fa8381-a1bc-4ca2-8049-0f65e11e083f","slug":"cve-2026-106580","externalId":"CVE-2026-106580","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106580 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.","cveId":"CVE-2026-106580","cvssScore":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284","CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/768bdd0dbb9a9ad743b6a6e557126b788b325970","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/ad178e41fce2afa6be2b91fb4e7f41c4c5448117","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00118,"epssPercentile":0.01587,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:44.560Z","addedAt":"2026-10-07T16:39:32.660Z","updatedAt":"2026-10-08T21:05:42.277Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106580","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106580","note":"authoritative record"}]},{"id":"f84632d9-6110-4053-90b6-e26e40e8f97e","slug":"cve-2026-107175","externalId":"CVE-2026-107175","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107175 — MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution…","description":"MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified.\n\nWhen a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted.\n\nSecurity impact:\n\n- Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure.\n\n- Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing.\n\nPreconditions:\n\n- An authenticated user with write access to at least one MISP event.\n\n- The user modifies the event's distribution or sharing_group_id field.\n\nAffected versions: <2.5.48","cveId":"CVE-2026-107175","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284","CWE-665"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MISP/MISP/commit/19a389d19","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.00207,"epssPercentile":0.09898,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:20.563Z","addedAt":"2026-10-07T14:39:35.132Z","updatedAt":"2026-10-07T16:39:32.164Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107175","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107175","note":"authoritative record"}]},{"id":"e8f446ec-2462-4664-97a1-75fe307bc24a","slug":"cve-2026-102781","externalId":"CVE-2026-102781","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102781 — Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired thro…","description":"Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.","cveId":"CVE-2026-102781","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ordasoft.com/","type":"advisory","title":"security@joomla.org"}],"epssScore":0.00239,"epssPercentile":0.13795,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T09:17:04.397Z","addedAt":"2026-10-07T10:39:38.674Z","updatedAt":"2026-10-07T20:39:40.051Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102781","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102781","note":"authoritative record"}]},{"id":"079cf771-771d-479d-b2c6-723cc1c3e334","slug":"cve-2026-104678","externalId":"CVE-2026-104678","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104678 — The CP Media Player  WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contr…","description":"The CP Media Player  WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player  WordPress plugin before 1.3.4 option that should require administrator access.","cveId":"CVE-2026-104678","cvssScore":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/d650ea4e-62f9-48a0-8cb3-e6761a95eeaa/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00168,"epssPercentile":0.05592,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T07:16:58.363Z","addedAt":"2026-10-07T08:39:33.373Z","updatedAt":"2026-10-07T16:39:31.817Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104678","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104678","note":"authoritative record"}]},{"id":"4fed75ab-519c-46b0-94bb-65b17699abac","slug":"cve-2026-103681","externalId":"CVE-2026-103681","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103681 — The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users w…","description":"The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.","cveId":"CVE-2026-103681","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/33674814-6329-4833-8d9a-3cca80dd5a14/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00152,"epssPercentile":0.03799,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T07:16:57.260Z","addedAt":"2026-10-07T08:39:33.313Z","updatedAt":"2026-10-07T16:39:31.753Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103681","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103681","note":"authoritative record"}]},{"id":"0e338e5c-3a65-4fe3-81ae-e6545856c14b","slug":"cve-2026-97680","externalId":"CVE-2026-97680","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97680 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to i…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.","cveId":"CVE-2026-97680","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-284"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00266,"epssPercentile":0.17001,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.780Z","addedAt":"2026-10-07T02:39:29.158Z","updatedAt":"2026-10-08T04:39:32.713Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97680","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97680","note":"authoritative record"}]},{"id":"92581120-ad2d-4baa-a2db-10a1cf4f6451","slug":"cve-2026-101329","externalId":"CVE-2026-101329","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101329 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.","cveId":"CVE-2026-101329","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0026,"epssPercentile":0.16222,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:32.837Z","addedAt":"2026-10-07T02:39:28.978Z","updatedAt":"2026-10-08T18:39:30.395Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101329","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101329","note":"authoritative record"}]},{"id":"717f7427-f320-4380-9685-f6cb3d5bc21e","slug":"cve-2026-104335","externalId":"CVE-2026-104335","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104335 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.","cveId":"CVE-2026-104335","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":0.00565,"epssPercentile":0.45159,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T00:17:20.553Z","addedAt":"2026-10-07T00:39:29.158Z","updatedAt":"2026-10-08T04:39:32.559Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104335","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104335","note":"authoritative record"}]},{"id":"bdf2d1b0-6c25-4327-8d77-f28aa96c445c","slug":"cve-2026-106503","externalId":"CVE-2026-106503","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106503 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.","cveId":"CVE-2026-106503","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"npm","product":"@backstage/plugin-scaffolder-backend","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend < 3.3.1","pkg:npm/%40backstage/plugin-scaffolder-backend >= 3.4.0, < 3.4.1","pkg:npm/%40backstage/plugin-scaffolder-backend >= 4.0.0, < 4.0.3","pkg:npm/%40backstage/plugin-scaffolder-backend >= 4.0.4, < 4.1.0"],"cwes":["CWE-178","CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-hmp2-4m7g-22cv","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/11c1384c0649b8ab26391c6a4e4f34b80ab0d188","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/a91ed72d540e80b62a73b39bb1563ff5018d52d1","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/e307e4f487103d815e484291b3fda778ab9983bf","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-hmp2-4m7g-22cv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-hmp2-4m7g-22cv","type":"advisory","title":"OSV GHSA-hmp2-4m7g-22cv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106503","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00357,"epssPercentile":0.2737,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:05.513Z","addedAt":"2026-10-06T22:39:33.219Z","updatedAt":"2026-10-07T18:42:42.838Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106503","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106503","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-HMP2-4M7G-22CV"}]},{"id":"61eb2d86-5fd6-4b27-879f-98961956808d","slug":"cve-2026-79797","externalId":"CVE-2026-79797","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79797 — An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application fu…","description":"An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.","cveId":"CVE-2026-79797","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.0027,"epssPercentile":0.17672,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:31.197Z","addedAt":"2026-10-06T20:39:33.293Z","updatedAt":"2026-10-08T04:39:32.448Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79797","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79797","note":"authoritative record"}]},{"id":"38c519be-e99f-4f25-bacd-815dd97141ec","slug":"cve-2026-86362","externalId":"CVE-2026-86362","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86362 — Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability.","description":"Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.","cveId":"CVE-2026-86362","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515843/dsa-2026-324-security-update-for-dell-system-update-dsu-vulnerabilities","type":"advisory","title":"security_alert@emc.com"}],"epssScore":0.00128,"epssPercentile":0.02146,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:16.717Z","addedAt":"2026-10-06T20:39:32.575Z","updatedAt":"2026-10-06T20:39:32.575Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86362","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86362","note":"authoritative record"}]},{"id":"47f79c6d-79de-4142-a67c-84f7078813ed","slug":"cve-2026-106513","externalId":"CVE-2026-106513","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106513 — MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the Simple…","description":"MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the download_attachments_on_load setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection.","cveId":"CVE-2026-106513","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-284","CWE-749"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MISP/MISP/commit/2ebf29f93","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.0064,"epssPercentile":0.49065,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:13.933Z","addedAt":"2026-10-06T20:39:32.472Z","updatedAt":"2026-10-07T18:39:30.452Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106513","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106513","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":3186,"totalPages":160,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:52:05.693Z","durationMs":41,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-284"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}