{"success":true,"data":{"threats":[{"id":"f440903e-ec2e-4de5-ac73-41f949818d3c","slug":"cve-2026-107733","externalId":"CVE-2026-107733","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107733 — SumatraPDF is a multi-format reader for Windows.","description":"SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, FrameOnCommand() handles CmdExec by passing a null current-tab pointer to RunWithExe(), which dereferences WindowTab::filePath. A local process in the same interactive Windows session, at an integrity level greater than or equal to SumatraPDF's under Windows UIPI, can dispatch CmdExec over DDE or WM_COPYDATA while no document tab is open, causing abrupt process termination and loss of unsaved state. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.","cveId":"CVE-2026-107733","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/013ad659c7de13fa15624d1f8a24e3231c50516b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-p2ph-2rvm-q37m","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T23:16:59.050Z","addedAt":"2026-10-09T01:06:18.718Z","updatedAt":"2026-10-09T01:06:18.718Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107733","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107733","note":"authoritative record"}]},{"id":"d044bd5e-26f0-44a0-924b-b3fc81e43ad6","slug":"cve-2026-107778","externalId":"CVE-2026-107778","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107778 — MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos client…","description":"MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.","cveId":"CVE-2026-107778","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/krb5/krb5","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/lib/krb5/krb/rd_cred.c#L77-L112","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/commit/48afa9abb89ab2176bb20624d87d010b9984fc08","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/pull/1511","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-null-pointer-dereference-via-krb5-rd-cred","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:52.630Z","addedAt":"2026-10-08T23:06:39.467Z","updatedAt":"2026-10-08T23:06:39.467Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107778","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107778","note":"authoritative record"}]},{"id":"dcc5782b-cc99-4a1f-82d3-ab9d61332ced","slug":"cve-2026-107708","externalId":"CVE-2026-107708","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107708 — MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leavin…","description":"MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.","cveId":"CVE-2026-107708","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/krb5/krb5","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/krb5/krb5/pull/1510","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:52.223Z","addedAt":"2026-10-08T23:06:39.452Z","updatedAt":"2026-10-08T23:06:39.452Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107708","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107708","note":"authoritative record"}]},{"id":"2b76d2b2-b525-4066-a9d9-ad6225b5ad4b","slug":"cve-2026-16165","externalId":"CVE-2026-16165","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16165 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a null pointer dereference.","cveId":"CVE-2026-16165","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:16:53.557Z","addedAt":"2026-10-08T14:40:02.952Z","updatedAt":"2026-10-08T21:05:49.459Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16165","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16165","note":"authoritative record"}]},{"id":"8427432b-290b-4641-adf2-b716d69b5e80","slug":"cve-2026-107613","externalId":"CVE-2026-107613","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107613 — A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker…","description":"A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition().","cveId":"CVE-2026-107613","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sourceforge.net/p/vnc-tight/bugs/1660/","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://www.tightvnc.com/whatsnew.php","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:16:50.020Z","addedAt":"2026-10-08T14:40:02.815Z","updatedAt":"2026-10-08T23:06:38.093Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107613","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107613","note":"authoritative record"}]},{"id":"779e295d-05cc-4b36-a5e0-9d627981797b","slug":"cve-2026-16182","externalId":"CVE-2026-16182","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16182 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an attacker to cause a denial of service due to a NULL pointer dereference in GraphQL variable processing.","cveId":"CVE-2026-16182","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:16.477Z","addedAt":"2026-10-08T14:40:02.662Z","updatedAt":"2026-10-08T21:05:48.932Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16182","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16182","note":"authoritative record"}]},{"id":"640be0d8-6e28-4d6d-9edd-9b2c5a32accd","slug":"cve-2026-107222","externalId":"CVE-2026-107222","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107222 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences an optional colorScale child without validating malformed rule structure. GetConditionalFormats reaches extractCondFmtCellIs and also indexes ColorScale.Cfvo, DataBar.Cfvo, and DataBar.Color without complete structural checks. When a crafted worksheet supplies a cellIs, dataBar, or colorScale rule missing expected children and the application calls GetConditionalFormats, missing formula, color, value-object, or colorScale data reaches an out-of-range index or nil dereference, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.","cveId":"CVE-2026-107222","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.7.0, < 2.11.1-0.20260812075026-be7a16390fa6"],"cwes":["CWE-129","CWE-476"],"tags":["nvd","status:received","osv","osv:ghsa-rxcj-4pj5-74gr","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/be7a16390fa69c71d3ca618c741d1a2b5ed362cd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2375","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-rxcj-4pj5-74gr","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-rxcj-4pj5-74gr","type":"advisory","title":"OSV GHSA-rxcj-4pj5-74gr"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00249,"epssPercentile":0.14856,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:34.800Z","addedAt":"2026-10-07T20:39:40.424Z","updatedAt":"2026-10-08T21:05:43.640Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107222","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107222","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RXCJ-4PJ5-74GR"}]},{"id":"d776b650-c938-467e-aaa4-7f7756579a9a","slug":"cve-2026-107213","externalId":"CVE-2026-107213","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107213 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.","cveId":"CVE-2026-107213","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.9.0, < 2.11.1-0.20260929015830-8ffeb07ec9a3"],"cwes":["CWE-476"],"tags":["nvd","status:received","osv","osv:ghsa-r7x5-4969-99p7","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/8ffeb07ec9a350410f6922313f6b7e4f5cc79241","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2434","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-r7x5-4969-99p7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-r7x5-4969-99p7","type":"advisory","title":"OSV GHSA-r7x5-4969-99p7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107213","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00291,"epssPercentile":0.19898,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:18.860Z","addedAt":"2026-10-07T18:39:31.677Z","updatedAt":"2026-10-08T21:05:43.387Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107213","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107213","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R7X5-4969-99P7"}]},{"id":"a6105209-9d0a-4534-b3be-b4a6bc7aed18","slug":"cve-2026-107169","externalId":"CVE-2026-107169","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107169 — A flaw was found in m17n-lib.","description":"A flaw was found in m17n-lib. An attacker could provide specially crafted or truncated UTF-8 input to trigger an unhandled null pointer dereference during text processing. This issue causes the application to crash unexpectedly, resulting in a Denial of Service (DoS).","cveId":"CVE-2026-107169","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107169","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547410","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00112,"epssPercentile":0.01282,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:19.023Z","addedAt":"2026-10-07T16:39:32.490Z","updatedAt":"2026-10-07T16:39:32.490Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107169","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107169","note":"authoritative record"}]},{"id":"1a339efa-f0f7-495d-a759-dfe4840969a2","slug":"cve-2026-107170","externalId":"CVE-2026-107170","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107170 — A flaw was found in m17n-lib.","description":"A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS).","cveId":"CVE-2026-107170","cvssScore":2.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107170","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547411","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00102,"epssPercentile":0.00888,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:20.387Z","addedAt":"2026-10-07T14:39:35.125Z","updatedAt":"2026-10-07T18:39:30.947Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107170","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107170","note":"authoritative record"}]},{"id":"6abd02b5-ac9a-401d-8090-3f7f3ae74aba","slug":"cve-2026-102169","externalId":"CVE-2026-102169","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102169 — On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID c…","description":"On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.","cveId":"CVE-2026-102169","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24810-security-advisory-0194","type":"advisory","title":"psirt@arista.com"}],"epssScore":0.00279,"epssPercentile":0.18644,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:12.197Z","addedAt":"2026-10-06T20:39:32.790Z","updatedAt":"2026-10-07T14:39:33.945Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102169","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102169","note":"authoritative record"}]},{"id":"eab7c808-0d1f-4b6a-a206-4b3dbbb255ce","slug":"cve-2026-104044","externalId":"CVE-2026-104044","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104044 — A flaw was found in sssd.","description":"A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized pointer and crashes. This failure disrupts authentication services on the host.","cveId":"CVE-2026-104044","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104044","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478664","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.0012,"epssPercentile":0.01649,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T02:17:03.760Z","addedAt":"2026-10-06T03:50:41.740Z","updatedAt":"2026-10-08T04:39:32.288Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104044","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104044","note":"authoritative record"}]},{"id":"741fa9b5-d47f-4de2-bef7-6368155da86b","slug":"cve-2026-104038","externalId":"CVE-2026-104038","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104038 — A flaw was found in sssd.","description":"A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations.","cveId":"CVE-2026-104038","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104038","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478980","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00222,"epssPercentile":0.11796,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T01:16:34.853Z","addedAt":"2026-10-06T01:50:41.305Z","updatedAt":"2026-10-07T22:39:36.063Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104038","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104038","note":"authoritative record"}]},{"id":"dea72acf-c3f5-44b0-8195-4ea2ff052cb9","slug":"cve-2026-93316","externalId":"CVE-2026-93316","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93316 — If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices.","description":"If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.","cveId":"CVE-2026-93316","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf","type":"advisory","title":"security@docker.com"}],"epssScore":0.00235,"epssPercentile":0.13183,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T18:17:37.780Z","addedAt":"2026-10-05T19:50:42.650Z","updatedAt":"2026-10-06T15:50:57.929Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93316","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93316","note":"authoritative record"}]},{"id":"4ff60d10-266d-4129-a968-3a2feab835c5","slug":"cve-2026-66859","externalId":"CVE-2026-66859","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66859 — NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.","description":"NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-66859","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-457","CWE-476"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34845,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:53.597Z","addedAt":"2026-10-02T13:50:40.954Z","updatedAt":"2026-10-02T17:50:40.472Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66859","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66859","note":"authoritative record"}]},{"id":"8af1f0e2-6ae2-4396-b9ab-986117d7c932","slug":"cve-2026-87117","externalId":"CVE-2026-87117","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87117 — NULL pointer dereference vulnerability in Apache Thrift PHP bindings.","description":"NULL pointer dereference vulnerability in Apache Thrift PHP bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-87117","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/y05tvpv19ow44j16gtbcy9ht7lb0qjpy","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34845,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:22.370Z","addedAt":"2026-10-02T13:50:40.800Z","updatedAt":"2026-10-02T19:50:41.393Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87117","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87117","note":"authoritative record"}]},{"id":"7eed3217-0234-4213-9120-ae97b6436d34","slug":"cve-2026-82357","externalId":"CVE-2026-82357","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82357 — RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device.","description":"RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.","cveId":"CVE-2026-82357","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-82357","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"}],"epssScore":0.00287,"epssPercentile":0.19435,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T20:17:32.363Z","addedAt":"2026-10-01T21:50:40.779Z","updatedAt":"2026-10-07T16:39:30.299Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82357","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82357","note":"authoritative record"}]},{"id":"cead87f9-5a1f-409f-9915-7cacbcf7f1dd","slug":"cve-2026-9032","externalId":"CVE-2026-9032","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-9032 — Tapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.","description":"Tapo C120 v1 and C200 v5\ncontain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without\nauthentication after initial setup and does not validate that a password field\nis present for certain authentication and encryption parameter combinations,\nallowing a malformed request from the same local network to crash the HTTPS service\n\n\n\n\n\n\n\n\n\n\n Successful exploitation may\ntemporarily make HTTPS management functions unavailable. Repeated malformed\nrequests may sustain the denial-of-service condition, and recovery may in some\ncases require a device reboot.","cveId":"CVE-2026-9032","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-476"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5321/","type":"advisory","title":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"epssScore":0.00143,"epssPercentile":0.03087,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:17:29.390Z","addedAt":"2026-10-01T19:50:41.136Z","updatedAt":"2026-10-06T20:39:29.498Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9032","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-9032","note":"authoritative record"}]},{"id":"4e5942b8-cadb-47ee-a7ca-dd7f966518dc","slug":"cve-2026-63686","externalId":"CVE-2026-63686","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63686 — A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backe…","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.","cveId":"CVE-2026-63686","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"apache","product":"http server","affectedVersions":[">= 2.4.0, < 2.4.69"],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","type":"vendor","title":"Vendor Advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/25","type":"advisory","title":"Mailing List"}],"epssScore":0.00478,"epssPercentile":0.39275,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T17:17:29.923Z","addedAt":"2026-10-01T17:50:42.905Z","updatedAt":"2026-10-05T19:50:42.251Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63686","note":"authoritative record"}]},{"id":"a3b446fb-7552-4fe1-9e16-11c83029afec","slug":"cve-2026-46729","externalId":"CVE-2026-46729","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46729 — NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","cveId":"CVE-2026-46729","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"apache","product":"http server","affectedVersions":[">= 2.4.60, < 2.4.69",">= 2.4.0, < 2.4.69"],"cwes":["CWE-476"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","type":"vendor","title":"Vendor Advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/13","type":"advisory","title":"Mailing List"}],"epssScore":0.00468,"epssPercentile":0.38541,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T16:17:44.293Z","addedAt":"2026-10-01T17:50:42.748Z","updatedAt":"2026-10-08T02:39:29.638Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46729","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":811,"totalPages":41,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T03:16:27.095Z","durationMs":36,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-476"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}