{"success":true,"data":{"threats":[{"id":"368769a8-762a-449b-ab46-5bba042c855a","slug":"cve-2026-107831","externalId":"CVE-2026-107831","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107831 — Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing …","description":"Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.","cveId":"CVE-2026-107831","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/banq/jivejdon","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-shortmessage.xml#L112-L118","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-subscription.xml#L75-L79","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/message/UpdateThreadNameAction.java#L19-L36","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/issues/28","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/jivejdon-through-5.0-csrf-via-get-based-account-and-thread-actions","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:30.947Z","addedAt":"2026-10-08T23:06:40.427Z","updatedAt":"2026-10-08T23:06:40.427Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107831","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107831","note":"authoritative record"}]},{"id":"13de7a76-f65e-4795-9a90-37a99cb54d19","slug":"cve-2026-78388","externalId":"CVE-2026-78388","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78388 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery whi…","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.","cveId":"CVE-2026-78388","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:18:02.727Z","addedAt":"2026-10-08T23:06:39.836Z","updatedAt":"2026-10-08T23:06:39.836Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78388","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78388","note":"authoritative record"}]},{"id":"33944c0c-4bb8-4261-a301-e301c37ff564","slug":"cve-2026-107337","externalId":"CVE-2026-107337","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107337 — The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)).","description":"The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.","cveId":"CVE-2026-107337","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-w8gq-4v5x-xrrm","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:20.687Z","addedAt":"2026-10-08T18:39:31.861Z","updatedAt":"2026-10-08T23:06:38.736Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107337","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107337","note":"authoritative record"}]},{"id":"d003fe6e-5605-45bf-a762-a0bee1b5d803","slug":"cve-2026-107295","externalId":"CVE-2026-107295","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107295 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools with the privileges and credentials of the local process; client-relayed approval decisions also leave requires_approval=True tools exposed. Binding to localhost does not prevent a browser page from reaching the loopback address. This issue is fixed in versions 1.107.4 and 2.28.0.","cveId":"CVE-2026-107295","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L","severity":"high","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.34.0, < 1.107.4","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.28.0","pkg:pypi/pydantic-ai-slim >= 1.34.0, < 1.107.4","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.28.0"],"cwes":["CWE-352","CWE-346"],"tags":["nvd","status:received","osv","osv:ghsa-h4xc-3qfq-jf93","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/d2690201a1834005d382dbf5c47e0ed94ef8bf46","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/dd2abbdfa029c9ad138e7cc0edd2eaeaf9ed69c0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7382","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7383","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.28.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h4xc-3qfq-jf93","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-h4xc-3qfq-jf93","type":"advisory","title":"OSV GHSA-h4xc-3qfq-jf93"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.237Z","addedAt":"2026-10-08T18:39:31.716Z","updatedAt":"2026-10-08T21:05:51.175Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107295","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107295","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-H4XC-3QFQ-JF93"}]},{"id":"e3dda1fb-0d68-425b-bdca-3a1a8efd54fb","slug":"cve-2026-66479","externalId":"CVE-2026-66479","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66479 — Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: fr…","description":"Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.","cveId":"CVE-2026-66479","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wpcomplete/vulnerability/wordpress-wpcomplete-plugin-2-9-5-6-csrf-to-stored-xss-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:18.707Z","addedAt":"2026-10-08T14:40:02.773Z","updatedAt":"2026-10-08T18:39:31.382Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66479","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66479","note":"authoritative record"}]},{"id":"5402b1bb-1ade-4c90-b78b-55ddbd426cbe","slug":"cve-2026-62142","externalId":"CVE-2026-62142","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62142 — Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a th…","description":"Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.","cveId":"CVE-2026-62142","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-2fa/vulnerability/wordpress-wp-2fa-plugin-4-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:18.553Z","addedAt":"2026-10-08T14:40:02.764Z","updatedAt":"2026-10-08T18:39:31.374Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62142","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62142","note":"authoritative record"}]},{"id":"04315dd4-1dd4-4aa0-a22d-7a0b8c399070","slug":"cve-2026-106611","externalId":"CVE-2026-106611","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106611 — Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: …","description":"Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: from n/a through 1.57.3.","cveId":"CVE-2026-106611","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/forminator/vulnerability/wordpress-forminator-plugin-1-57-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:15.013Z","addedAt":"2026-10-08T14:40:02.578Z","updatedAt":"2026-10-08T18:39:31.328Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106611","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106611","note":"authoritative record"}]},{"id":"6f6e481c-14eb-46a5-a3d1-ef4a2230209f","slug":"cve-2026-102784","externalId":"CVE-2026-102784","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102784 — Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla …","description":"Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.","cveId":"CVE-2026-102784","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.balbooa.com/gridbox","type":"advisory","title":"security@joomla.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:12.023Z","addedAt":"2026-10-08T14:40:02.443Z","updatedAt":"2026-10-08T23:06:37.868Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102784","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102784","note":"authoritative record"}]},{"id":"f2ec6be1-b1dc-4a01-9734-4c05e1f29f51","slug":"cve-2026-105260","externalId":"CVE-2026-105260","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105260 — The Database Addon For WPForms ( wpforms entries )  WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and perf…","description":"The Database Addon For WPForms ( wpforms entries )  WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.","cveId":"CVE-2026-105260","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/532d21c1-448f-422d-8d58-a76e9cff99e4/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00097,"epssPercentile":0.00693,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:41.130Z","addedAt":"2026-10-08T06:39:29.680Z","updatedAt":"2026-10-08T21:05:46.967Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105260","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105260","note":"authoritative record"}]},{"id":"5717e9b3-fd00-46d4-b123-574e02d07376","slug":"cve-2025-70522","externalId":"CVE-2025-70522","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-70522 — The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request …","description":"The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.","cveId":"CVE-2025-70522","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://download.fanvil.com/Firmware/Release/PA2S/","type":"advisory","title":"cve@mitre.org"},{"url":"https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00164,"epssPercentile":0.05106,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:16:55.240Z","addedAt":"2026-10-07T16:39:32.388Z","updatedAt":"2026-10-09T03:06:17.355Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70522","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-70522","note":"authoritative record"}]},{"id":"12691e47-69ff-49f4-bb4a-fbe6cd04e90a","slug":"cve-2025-70517","externalId":"CVE-2025-70517","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-70517 — The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request …","description":"The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.","cveId":"CVE-2025-70517","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://download.fanvil.com/Firmware/Release/X7A/","type":"advisory","title":"cve@mitre.org"},{"url":"https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.fanvil.com/products/p1/x/20210921/5043.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00164,"epssPercentile":0.05105,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:16:52.690Z","addedAt":"2026-10-07T16:39:32.353Z","updatedAt":"2026-10-09T03:06:17.328Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70517","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-70517","note":"authoritative record"}]},{"id":"43397ffd-057a-4c10-9ace-722ce2005086","slug":"cve-2026-45161","externalId":"CVE-2026-45161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-45161 — wger is a free, open-source workout and fitness manager.","description":"wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.","cveId":"CVE-2026-45161","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":"PyPI","product":"wger","affectedVersions":["pkg:pypi/wger <= 2.1"],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-xf64-4pmc-h8qf","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wger-project/wger/releases/tag/2.6","type":"other","title":"OSV web"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-xf64-4pmc-h8qf","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-xf64-4pmc-h8qf","type":"advisory","title":"OSV GHSA-xf64-4pmc-h8qf"},{"url":"https://github.com/wger-project/wger","type":"vendor","title":"OSV package"}],"epssScore":0.00088,"epssPercentile":0.00364,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:10.087Z","addedAt":"2026-10-07T14:39:35.251Z","updatedAt":"2026-10-07T18:42:45.583Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-45161","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-XF64-4PMC-H8QF"}]},{"id":"ca09eda2-de3c-431e-bfe6-6be9314d7495","slug":"cve-2026-106216","externalId":"CVE-2026-106216","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106216 — Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social enginee…","description":"Cross-site request forgery in ReadingList in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106216","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/518076654","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.0018,"epssPercentile":0.06945,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:48.210Z","addedAt":"2026-10-06T20:39:30.765Z","updatedAt":"2026-10-09T03:06:16.745Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106216","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106216","note":"authoritative record"}]},{"id":"04d1e85e-7567-4081-9b42-de99ca78e7c8","slug":"cve-2026-105706","externalId":"CVE-2026-105706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105706 — A weakness has been identified in SourceCodester Drug Recommendation System 1.0.","description":"A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.","cveId":"CVE-2026-105706","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352","CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/hackliu/Vulnerability-Reports/blob/master/Drug-Recommender-Web-App/VULN-06-CSRF-Missing-Tokens.md","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105706","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/992055","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413699","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413699/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://www.sourcecodester.com/","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00159,"epssPercentile":0.04401,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T05:16:38.010Z","addedAt":"2026-10-06T05:50:40.722Z","updatedAt":"2026-10-06T15:50:59.142Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105706","note":"authoritative record"}]},{"id":"574dfcc3-3c29-458a-a949-036674c5a35c","slug":"cve-2026-105783","externalId":"CVE-2026-105783","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105783 — Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks.","description":"Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP or HTTPS origins. The desktop confirmation dialog does not identify the requesting origin, so a victim who approves the generic prompt authorizes the attacking page, which then receives the permanent API token. The token provides ongoing read and write access to notes, folders, tags, resources, and master keys. This issue is fixed in version 3.7.13.","cveId":"CVE-2026-105783","cvssScore":8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346","CWE-352"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/laurent22/joplin/commit/27ae5c0d404ee47ad24862cce917dda6eb2930b7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/pull/16276","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/releases/tag/v3.7.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9728-v7ww-mxjv","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00145,"epssPercentile":0.03242,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T00:16:33.770Z","addedAt":"2026-10-06T01:50:41.224Z","updatedAt":"2026-10-06T15:50:58.959Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105783","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105783","note":"authoritative record"}]},{"id":"2e01e0a1-27c1-4f62-8afc-fea1f7f86461","slug":"cve-2026-102778","externalId":"CVE-2026-102778","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102778 — Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a sh…","description":"Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option \"Share article links\" is on. It took the address of the article from the shared link and printed it into the page without checking or escaping it; with the link type \"Image Page with Redirect\" it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another web site. Nothing on the server is changed or read by the server.","cveId":"CVE-2026-102778","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352","CWE-601"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.svenbluege.de/","type":"advisory","title":"security@joomla.org"}],"epssScore":0.00151,"epssPercentile":0.03696,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T16:17:04.593Z","addedAt":"2026-10-05T17:50:42.860Z","updatedAt":"2026-10-06T15:50:57.792Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102778","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102778","note":"authoritative record"}]},{"id":"9583667b-3b25-4caa-9596-a19363132e44","slug":"cve-2026-102776","externalId":"CVE-2026-102776","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102776 — Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which t…","description":"Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out; choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way; orders are not affected.","cveId":"CVE-2026-102776","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.svenbluege.de/","type":"advisory","title":"security@joomla.org"}],"epssScore":0.00151,"epssPercentile":0.03696,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T16:17:04.453Z","addedAt":"2026-10-05T17:50:42.854Z","updatedAt":"2026-10-06T15:50:57.785Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102776","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102776","note":"authoritative record"}]},{"id":"a74af3f4-b5be-43f1-9882-102d41841365","slug":"cve-2026-104407","externalId":"CVE-2026-104407","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104407 — Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue…","description":"Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.","cveId":"CVE-2026-104407","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/powerpress/vulnerability/wordpress-powerpress-podcasting-plugin-11-17-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00097,"epssPercentile":0.00703,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:08.487Z","addedAt":"2026-10-05T09:50:40.838Z","updatedAt":"2026-10-06T15:50:57.366Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104407","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104407","note":"authoritative record"}]},{"id":"1222ed74-ab44-41b9-bc01-0f7a3948e0e1","slug":"cve-2026-105292","externalId":"CVE-2026-105292","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105292 — Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chate…","description":"Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.","cveId":"CVE-2026-105292","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Chaterm/Chaterm","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Chaterm/Chaterm/blob/v0.12.0/src/main/index.ts#L3442-L3455","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Chaterm/Chaterm/commit/41f747f17845cd980f289cc9ea8ff9978b6f7ad6","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Chaterm/Chaterm/pull/2326","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Chaterm/Chaterm/releases/tag/v0.12.1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/chaterm-before-0.12.1-login-csrf-via-chaterm-oauth-callback","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00159,"epssPercentile":0.04415,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T01:16:28.630Z","addedAt":"2026-10-05T01:50:40.077Z","updatedAt":"2026-10-07T00:39:29.087Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105292","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105292","note":"authoritative record"}]},{"id":"a8a602fe-e2b4-4444-92f6-6dbeb54e61dc","slug":"cve-2026-93549","externalId":"CVE-2026-93549","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93549 — The CoCart  WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's R…","description":"The CoCart  WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.","cveId":"CVE-2026-93549","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-352"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00141,"epssPercentile":0.0297,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T07:16:34.180Z","addedAt":"2026-10-04T07:50:39.872Z","updatedAt":"2026-10-06T15:50:56.576Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93549","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93549","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":795,"totalPages":40,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T04:01:04.390Z","durationMs":19,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-352"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}