{"success":true,"data":{"threats":[{"id":"169c981d-6fa7-431c-aeb0-4680532b6441","slug":"cve-2026-107396","externalId":"CVE-2026-107396","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107396 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107396","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7619","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.417Z","addedAt":"2026-10-08T21:05:53.210Z","updatedAt":"2026-10-08T21:05:53.210Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107396","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107396","note":"authoritative record"}]},{"id":"dee025a4-930f-41fb-b334-be53587532b2","slug":"cve-2026-71478","externalId":"CVE-2026-71478","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71478 — league/commonmark is a PHP library for parsing and rendering CommonMark Markdown.","description":"league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.","cveId":"CVE-2026-71478","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79","CWE-86","CWE-692"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/thephpleague/commonmark/releases/tag/2.9.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00355,"epssPercentile":0.27139,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-06T22:18:31.750Z","addedAt":"2026-08-06T23:50:25.836Z","updatedAt":"2026-09-10T21:50:34.230Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71478","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71478","note":"authoritative record"}]},{"id":"ad760041-73f2-4b7e-99ad-50c79113de43","slug":"cve-2024-42214","externalId":"CVE-2024-42214","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2024-42214 — HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.","description":"HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.","cveId":"CVE-2024-42214","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294","type":"advisory","title":"psirt@hcl.com"}],"epssScore":0.0033,"epssPercentile":0.24068,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-17T14:17:18.863Z","addedAt":"2026-10-02T01:50:40.968Z","updatedAt":"2026-10-02T01:50:40.968Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42214","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2024-42214","note":"authoritative record"}]},{"id":"d8160041-4b5e-4ff3-9826-dc60b31031ca","slug":"cve-2024-23569","externalId":"CVE-2024-23569","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2024-23569 — HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header","description":"HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header","cveId":"CVE-2024-23569","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294","type":"advisory","title":"psirt@hcl.com"}],"epssScore":0.00297,"epssPercentile":0.20497,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-17T14:17:17.110Z","addedAt":"2026-10-02T01:50:40.920Z","updatedAt":"2026-10-02T01:50:40.920Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23569","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2024-23569","note":"authoritative record"}]},{"id":"96b81ad5-74ba-4773-bb25-90218b88cba0","slug":"cve-2025-20240","externalId":"CVE-2025-20240","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-20240 — A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected c…","description":"A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device.\r\n\r This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.","cveId":"CVE-2025-20240","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-xss-VWyDgjOU","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.0029,"epssPercentile":0.19734,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-09-24T18:15:34.333Z","addedAt":"2026-09-26T01:50:41.525Z","updatedAt":"2026-09-26T01:50:41.525Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-20240","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-20240","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":5,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:46:48.840Z","durationMs":18,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-692"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}