{"success":true,"data":{"threats":[{"id":"e4ac6c5c-95f0-40a6-a0cf-0c6c44443fb1","slug":"cve-2026-55280","externalId":"CVE-2026-55280","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55280 — In multiple locations, there is a possible out-of-bounds write due to uninitialized data.","description":"In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-55280","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["16.0","17.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00231,"epssPercentile":0.12778,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:24.207Z","addedAt":"2026-10-05T19:50:42.931Z","updatedAt":"2026-10-07T16:39:30.381Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55280","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55280","note":"authoritative record"}]},{"id":"4ff60d10-266d-4129-a968-3a2feab835c5","slug":"cve-2026-66859","externalId":"CVE-2026-66859","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66859 — NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.","description":"NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-66859","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457","CWE-476"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34845,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:53.597Z","addedAt":"2026-10-02T13:50:40.954Z","updatedAt":"2026-10-02T17:50:40.472Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66859","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66859","note":"authoritative record"}]},{"id":"e908b7f7-c7a5-4881-9800-32fd3cc8de85","slug":"cve-2026-18397","externalId":"CVE-2026-18397","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…","description":"This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.\n\nThe attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.","cveId":"CVE-2026-18397","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-252","CWE-347","CWE-457"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.thalesgroup.com/en/product-security-incident-response","type":"advisory","title":"psirt@thalesgroup.com"}],"epssScore":0.00337,"epssPercentile":0.25018,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:01.220Z","addedAt":"2026-10-01T23:50:39.516Z","updatedAt":"2026-10-02T21:50:40.069Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18397","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18397","note":"authoritative record"}]},{"id":"73ad0427-398a-40bf-9eea-6fbcf8db79e7","slug":"cve-2026-103436","externalId":"CVE-2026-103436","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103436 — apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstat…","description":"apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf(\"%*s %*s %s\", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.","cveId":"CVE-2026-103436","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493140","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240","type":"advisory","title":"cve@mitre.org"},{"url":"https://sourceforge.net/projects/apcupsd/","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00293,"epssPercentile":0.20016,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:09.700Z","addedAt":"2026-09-30T17:50:47.779Z","updatedAt":"2026-10-02T17:50:40.000Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103436","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103436","note":"authoritative record"}]},{"id":"38def30c-dcc9-40d8-b2b4-188e8bc0a91d","slug":"cve-2026-102717","externalId":"CVE-2026-102717","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102717 — MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash","description":"MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash","cveId":"CVE-2026-102717","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-457"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-hp64-f44f-wjw6","type":"advisory","title":"emo@eclipse.org"}],"epssScore":0.00263,"epssPercentile":0.16601,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T15:22:21.957Z","addedAt":"2026-09-30T15:50:43.587Z","updatedAt":"2026-09-30T21:50:44.281Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102717","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102717","note":"authoritative record"}]},{"id":"5258a00d-a38b-46c6-8a3c-9c5dc775727c","slug":"cve-2026-95332","externalId":"CVE-2026-95332","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95332 — Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sa…","description":"Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-95332","cvssScore":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 154.0.8037.57"],"cwes":["CWE-457"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/546639650","type":"advisory","title":"Permissions Required"}],"epssScore":0.00283,"epssPercentile":0.19029,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T18:17:25.680Z","addedAt":"2026-09-29T19:50:42.039Z","updatedAt":"2026-09-30T15:50:41.965Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95332","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95332","note":"authoritative record"}]},{"id":"896e9d95-a328-41c3-94a8-a018aff1767c","slug":"cve-2026-100806","externalId":"CVE-2026-100806","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100806 — Uninitialized memory in the Graphics: WebGPU component.","description":"Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.","cveId":"CVE-2026-100806","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2060408","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-100/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-101/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-103/","type":"advisory","title":"security@mozilla.org"}],"epssScore":0.00266,"epssPercentile":0.16965,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:45.700Z","addedAt":"2026-09-29T13:50:39.586Z","updatedAt":"2026-09-30T19:50:42.688Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100806","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100806","note":"authoritative record"}]},{"id":"d7f82bfc-1a0a-4cef-8151-f570aacb2c24","slug":"cve-2026-100802","externalId":"CVE-2026-100802","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100802 — Uninitialized memory in the Graphics: WebGPU component.","description":"Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.","cveId":"CVE-2026-100802","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2057833","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-101/","type":"advisory","title":"security@mozilla.org"}],"epssScore":0.00257,"epssPercentile":0.15953,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:45.287Z","addedAt":"2026-09-29T13:50:39.568Z","updatedAt":"2026-09-30T19:50:42.669Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100802","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100802","note":"authoritative record"}]},{"id":"e20d18a0-6f1d-4658-970c-19d80844e22d","slug":"cve-2026-100799","externalId":"CVE-2026-100799","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100799 — Uninitialized memory in the Graphics: WebGPU component.","description":"Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.","cveId":"CVE-2026-100799","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2056217","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-101/","type":"advisory","title":"security@mozilla.org"}],"epssScore":0.00257,"epssPercentile":0.15953,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:44.973Z","addedAt":"2026-09-29T13:50:39.556Z","updatedAt":"2026-09-30T19:50:42.653Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100799","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100799","note":"authoritative record"}]},{"id":"ce9dd486-3b6a-40b0-a22e-9f0cd1354bb1","slug":"cve-2026-100783","externalId":"CVE-2026-100783","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100783 — Uninitialized memory in the Audio/Video component.","description":"Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.","cveId":"CVE-2026-100783","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","severity":"medium","vendor":"mozilla","product":"firefox","affectedVersions":["< 115.42.0",">= 116.0, < 140.17.0",">= 141.0, < 153.4.0",">= 154.0.0, < 157.0.0","< 140.17.0",">= 154.0, < 157.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2069804","type":"advisory","title":"Permissions Required"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-100/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-98/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-99/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-101/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-102/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-103/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0028,"epssPercentile":0.18711,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:43.247Z","addedAt":"2026-09-29T13:50:39.473Z","updatedAt":"2026-10-05T13:50:40.627Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100783","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100783","note":"authoritative record"}]},{"id":"04b50272-5026-48f3-b44f-99483e75c124","slug":"cve-2026-100759","externalId":"CVE-2026-100759","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100759 — Uninitialized memory in the Storage: Quota Manager component.","description":"Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.","cveId":"CVE-2026-100759","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2054736","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-100/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-98/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-99/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-101/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-102/","type":"advisory","title":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-103/","type":"advisory","title":"security@mozilla.org"}],"epssScore":0.00329,"epssPercentile":0.2394,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:40.213Z","addedAt":"2026-09-29T13:50:39.352Z","updatedAt":"2026-10-01T15:50:40.240Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100759","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100759","note":"authoritative record"}]},{"id":"1d2e90d9-8c63-46c0-8996-ba42f07eb8f3","slug":"cve-2026-19492","externalId":"CVE-2026-19492","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19492 — IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in …","description":"IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.","cveId":"CVE-2026-19492","cvssScore":3.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","severity":"low","vendor":"ibm","product":"power system s1122 (9824-22a) firmware","affectedVersions":[">= fw1110.00, < fw1110.32",">= fw1120.00, < fw1120.02",">= fw1060.00, < fw1060.82"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://www.ibm.com/support/pages/node/7289137"],"references":[{"url":"https://www.ibm.com/support/pages/node/7289137","type":"patch","title":"Patch"}],"epssScore":0.00115,"epssPercentile":0.01428,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T15:17:20.553Z","addedAt":"2026-09-24T15:50:40.198Z","updatedAt":"2026-09-30T15:50:40.779Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19492","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19492","note":"authoritative record"}]},{"id":"ded63ede-739a-4ebe-9625-b0a5a6cff26b","slug":"cve-2026-58731","externalId":"CVE-2026-58731","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58731 — In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data.","description":"In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58731","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"google","product":"android","affectedVersions":[],"cwes":["CWE-125","CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00097,"epssPercentile":0.00698,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T19:17:33.150Z","addedAt":"2026-09-15T19:50:37.583Z","updatedAt":"2026-09-18T13:50:50.298Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58731","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58731","note":"authoritative record"}]},{"id":"4bb5558e-2684-4031-9759-e85134202b3b","slug":"cve-2026-58721","externalId":"CVE-2026-58721","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58721 — In multiple locations, there is a possible information disclosure due to uninitialized memory use.","description":"In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58721","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"google","product":"android","affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00094,"epssPercentile":0.00561,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T19:17:32.753Z","addedAt":"2026-09-15T19:50:37.565Z","updatedAt":"2026-09-18T13:50:50.274Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58721","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58721","note":"authoritative record"}]},{"id":"3ce26f13-8f9f-4ec8-8830-72c4e7fcd363","slug":"cve-2026-91963","externalId":"CVE-2026-91963","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-91963 — FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel.","description":"FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.","cveId":"CVE-2026-91963","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"freerdp","product":"freerdp","affectedVersions":[">= 2.0.0, < 3.31.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00665,"epssPercentile":0.50239,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T16:17:51.907Z","addedAt":"2026-09-15T17:50:37.310Z","updatedAt":"2026-09-23T21:50:37.715Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91963","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-91963","note":"authoritative record"}]},{"id":"9ba8b7ce-73b4-4309-b3b0-c3e1ce24ec54","slug":"cve-2026-16141","externalId":"CVE-2026-16141","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16141 — OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to…","description":"OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.","cveId":"CVE-2026-16141","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457","CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.runzero.com/advisories/openbmc-ipmi-auth-bypass-rakp-cve-2026-16141/","type":"advisory","title":"44488dab-36db-4358-99f9-bc116477f914"},{"url":"https://www.runzero.com/blog/lights-out-exposed/","type":"advisory","title":"44488dab-36db-4358-99f9-bc116477f914"}],"epssScore":0.00391,"epssPercentile":0.3105,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T14:16:50.430Z","addedAt":"2026-09-15T15:50:39.240Z","updatedAt":"2026-09-18T19:50:37.462Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16141","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16141","note":"authoritative record"}]},{"id":"08fa3a49-9eb8-4385-9757-c71b696f9ca4","slug":"cve-2026-92052","externalId":"CVE-2026-92052","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92052 — Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component.","description":"Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.","cveId":"CVE-2026-92052","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"mozilla","product":"firefox","affectedVersions":["< 153.3.0",">= 154.0.0, < 156.0.0",">= 154.0, < 156.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2061499","type":"advisory","title":"Permissions Required"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-90/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-93/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-94/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-96/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00239,"epssPercentile":0.13771,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T13:16:56.940Z","addedAt":"2026-09-15T13:50:41.403Z","updatedAt":"2026-10-05T19:50:41.898Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92052","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92052","note":"authoritative record"}]},{"id":"fcf37e3f-bb3b-4506-addd-8b4bfb4d74d9","slug":"cve-2026-84564","externalId":"CVE-2026-84564","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84564 — An uninitialized memory issue was addressed with improved memory initialization.","description":"An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may result in disclosure of process memory.","cveId":"CVE-2026-84564","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":"apple","product":"ipados","affectedVersions":["< 26.7",">= 15.0, < 15.8",">= 26.0, < 26.7","< 27.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.apple.com/en-us/149034","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149035","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149036","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149037","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149038","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149041","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149042","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149043","type":"vendor","title":"Release Notes"}],"epssScore":0.00383,"epssPercentile":0.30199,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T21:17:32.570Z","addedAt":"2026-09-14T21:50:39.544Z","updatedAt":"2026-09-18T17:50:36.161Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84564","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84564","note":"authoritative record"}]},{"id":"b08bddbc-49d4-49b2-a466-78d67aa2cd7b","slug":"cve-2026-65405","externalId":"CVE-2026-65405","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-65405 — A memory initialization issue was addressed with improved memory handling.","description":"A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.","cveId":"CVE-2026-65405","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":"apple","product":"ipados","affectedVersions":["< 26.7",">= 15.0, < 15.8",">= 26.0, < 26.7","< 27.0"],"cwes":["CWE-457"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.apple.com/en-us/149034","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149035","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149036","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149037","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149038","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149041","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149042","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/149043","type":"vendor","title":"Release Notes"}],"epssScore":0.00163,"epssPercentile":0.05053,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T21:17:24.083Z","addedAt":"2026-09-14T21:50:39.152Z","updatedAt":"2026-09-16T19:50:39.307Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65405","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-65405","note":"authoritative record"}]},{"id":"896f5ae3-7eac-476d-84e0-3122fcad5098","slug":"cve-2026-84391","externalId":"CVE-2026-84391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84391 — A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert att…","description":"A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>","cveId":"CVE-2026-84391","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-172","type":"advisory","title":"psirt@fortinet.com"}],"epssScore":0.00411,"epssPercentile":0.33276,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T17:18:37.520Z","addedAt":"2026-09-08T17:50:35.179Z","updatedAt":"2026-09-08T19:50:38.238Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84391","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":95,"totalPages":5,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:25:39.757Z","durationMs":26,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-457"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}