{"success":true,"data":{"threats":[{"id":"1ad47184-9cf0-491a-9a2e-fb83184528d2","slug":"cve-2026-107792","externalId":"CVE-2026-107792","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107792 — Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authe…","description":"Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.","cveId":"CVE-2026-107792","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/banq/jivejdon","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-message.xml#L136-L140","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/message/UpdateThreadToForumAction.java#L25-L62","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/banq/jivejdon/issues/28","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/jivejdon-through-commit-ee67a65e-missing-authorization-via-message-threadtoforum-save-thread-move","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:29.293Z","addedAt":"2026-10-08T23:06:40.231Z","updatedAt":"2026-10-08T23:06:40.231Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107792","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107792","note":"authoritative record"}]},{"id":"0adecb32-bf9b-4f81-acaa-d48927ceaf99","slug":"cve-2026-107725","externalId":"CVE-2026-107725","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107725 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.","description":"Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.","cveId":"CVE-2026-107725","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.hazelcast.com/hazelcast/5.7/release-notes/community","type":"advisory","title":"security-advisories@github.com"},{"url":"https://docs.hazelcast.com/hazelcast/5.7/release-notes/enterprise","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd335cefe0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/hazelcast/hazelcast/security/advisories/GHSA-w294-6q5q-53p8","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:28.967Z","addedAt":"2026-10-08T23:06:40.193Z","updatedAt":"2026-10-08T23:06:40.193Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107725","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107725","note":"authoritative record"}]},{"id":"e7710434-db62-4435-9d72-5db3a0047c7d","slug":"cve-2026-107395","externalId":"CVE-2026-107395","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to that session, as long as the containing event is accessible. The missing access check can disclose session metadata such as the title, description, and conveners. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107395","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/524e8e93eadcd8484905b1147020a35f5dce6038","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-6p4f-j8j6-463q","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.250Z","addedAt":"2026-10-08T21:05:53.094Z","updatedAt":"2026-10-08T21:05:53.094Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107395","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107395","note":"authoritative record"}]},{"id":"8d5b7777-8f54-478c-ad6a-f524ec124783","slug":"cve-2026-93860","externalId":"CVE-2026-93860","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93860 — In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly witho…","description":"In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.","cveId":"CVE-2026-93860","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://launchpad.net/bugs/2162789","type":"advisory","title":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-044.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:30.993Z","addedAt":"2026-10-08T18:39:31.968Z","updatedAt":"2026-10-08T23:06:39.002Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93860","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93860","note":"authoritative record"}]},{"id":"8dd3dfc4-4151-4db7-b46f-1391a6721040","slug":"cve-2026-12859","externalId":"CVE-2026-12859","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-12859 — Missing Authorization vulnerability in Caz Informatics Services Trade Inc.","description":"Missing Authorization vulnerability in Caz Informatics Services Trade Inc. Advancity ALMS Cloud allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Advancity ALMS Cloud: through 2026-10-08. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.","cveId":"CVE-2026-12859","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1276","type":"advisory","title":"iletisim@usom.gov.tr"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:48.010Z","addedAt":"2026-10-08T16:39:35.849Z","updatedAt":"2026-10-08T21:05:50.142Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12859","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-12859","note":"authoritative record"}]},{"id":"726dd283-fbc5-4e4e-abe3-86a494516a37","slug":"cve-2026-107623","externalId":"CVE-2026-107623","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107623 — A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak.","description":"A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout.","cveId":"CVE-2026-107623","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107623","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547957","type":"advisory","title":"secalert@redhat.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:46.017Z","addedAt":"2026-10-08T16:39:35.786Z","updatedAt":"2026-10-08T21:05:50.127Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107623","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107623","note":"authoritative record"}]},{"id":"889d87c4-2821-40df-ae48-954fdf163988","slug":"cve-2026-62128","externalId":"CVE-2026-62128","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62128 — Missing Authorization vulnerability in Creator LMS Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.T…","description":"Missing Authorization vulnerability in Creator LMS Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through 1.2.21.","cveId":"CVE-2026-62128","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-21-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:18.410Z","addedAt":"2026-10-08T14:40:02.757Z","updatedAt":"2026-10-08T18:39:31.367Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62128","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62128","note":"authoritative record"}]},{"id":"eca4ceea-6402-4131-9994-82c90710cc6d","slug":"cve-2026-106600","externalId":"CVE-2026-106600","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106600 — Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.T…","description":"Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 4.18.0.","cveId":"CVE-2026-106600","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-18-0-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:14.740Z","addedAt":"2026-10-08T14:40:02.558Z","updatedAt":"2026-10-08T18:39:31.312Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106600","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106600","note":"authoritative record"}]},{"id":"b17704b8-f0c5-4843-972f-28afde8c6041","slug":"cve-2026-106596","externalId":"CVE-2026-106596","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106596 — Missing Authorization vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Exploiting Incorrectly Configured Acce…","description":"Missing Authorization vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Composer Website Builder: from n/a through 45.16.3.","cveId":"CVE-2026-106596","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-plugin-45-16-3-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:14.600Z","addedAt":"2026-10-08T14:40:02.550Z","updatedAt":"2026-10-08T18:39:31.305Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106596","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106596","note":"authoritative record"}]},{"id":"e294cba3-01b0-4a1f-8d0b-4edd4e38166d","slug":"cve-2026-105891","externalId":"CVE-2026-105891","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105891 — Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control S…","description":"Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1.","cveId":"CVE-2026-105891","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-30-0-1-broken-access-control-vulnerability-2?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:14.070Z","addedAt":"2026-10-08T14:40:02.533Z","updatedAt":"2026-10-08T18:39:31.290Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105891","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105891","note":"authoritative record"}]},{"id":"8862e508-064f-45e3-bdd7-fe7d56f85291","slug":"cve-2026-105888","externalId":"CVE-2026-105888","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105888 — Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control S…","description":"Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1.","cveId":"CVE-2026-105888","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-30-0-1-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:13.790Z","addedAt":"2026-10-08T14:40:02.517Z","updatedAt":"2026-10-08T18:39:31.275Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105888","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105888","note":"authoritative record"}]},{"id":"af048115-5d06-45ac-99c3-d1e3ffbf3416","slug":"cve-2026-105886","externalId":"CVE-2026-105886","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105886 — Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Securit…","description":"Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5.","cveId":"CVE-2026-105886","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/ultimate-post-kit/vulnerability/wordpress-ultimate-post-kit-plugin-4-5-5-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:13.403Z","addedAt":"2026-10-08T14:40:02.501Z","updatedAt":"2026-10-08T18:39:31.260Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105886","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105886","note":"authoritative record"}]},{"id":"0e28f5b7-2e5b-45bd-8d67-a0df51023129","slug":"cve-2026-105878","externalId":"CVE-2026-105878","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105878 — Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configu…","description":"Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.","cveId":"CVE-2026-105878","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/yith-woocommerce-product-bundles/vulnerability/wordpress-yith-woocommerce-product-bundles-plugin-2-29-0-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:13.187Z","addedAt":"2026-10-08T14:40:02.492Z","updatedAt":"2026-10-08T18:39:31.252Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105878","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105878","note":"authoritative record"}]},{"id":"ebb0f7ea-a0c9-475e-bed6-00cfe6b8ecd6","slug":"cve-2026-103072","externalId":"CVE-2026-103072","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103072 — Missing Authorization vulnerability in VillaTheme VillaTheme Core villatheme-core allows Exploiting Incorrectly Configured Access Control Security …","description":"Missing Authorization vulnerability in VillaTheme VillaTheme Core villatheme-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VillaTheme Core: from n/a through 1.0.5.","cveId":"CVE-2026-103072","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/villatheme-core/vulnerability/wordpress-villatheme-core-plugin-1-0-5-broken-access-control-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:12.300Z","addedAt":"2026-10-08T14:40:02.459Z","updatedAt":"2026-10-08T18:39:31.217Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103072","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103072","note":"authoritative record"}]},{"id":"89ccc103-e9a8-4a25-9e10-e31c40acd051","slug":"cve-2026-105190","externalId":"CVE-2026-105190","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105190 — The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account,…","description":"The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.","cveId":"CVE-2026-105190","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/d167e184-af71-4ff8-8a2d-a665f7539fe4/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:44.607Z","addedAt":"2026-10-08T12:39:41.291Z","updatedAt":"2026-10-08T21:05:48.170Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105190","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105190","note":"authoritative record"}]},{"id":"8d74a2e2-2f85-4df8-af39-d5f8f9bad47f","slug":"cve-2026-104671","externalId":"CVE-2026-104671","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104671 — The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allow…","description":"The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.","cveId":"CVE-2026-104671","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/6ecea67e-8019-4ef2-bd27-a9da7dc27d43/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:44.303Z","addedAt":"2026-10-08T12:39:41.276Z","updatedAt":"2026-10-08T21:05:48.087Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104671","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104671","note":"authoritative record"}]},{"id":"b14b90ab-9ded-4213-9e75-d19fa275cc8c","slug":"cve-2026-104660","externalId":"CVE-2026-104660","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104660 — Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMai…","description":"Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.","cveId":"CVE-2026-104660","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/59","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:44.160Z","addedAt":"2026-10-08T12:39:41.269Z","updatedAt":"2026-10-08T23:06:37.522Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104660","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104660","note":"authoritative record"}]},{"id":"122de44c-a173-4d4c-8b77-b1b6668803f2","slug":"cve-2026-71895","externalId":"CVE-2026-71895","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71895 — An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended f…","description":"An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler.\n\n\n\nThe impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster.\n\n\n\nThis issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-71895","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/8g6p34cf0m7fnox5qpm99r50g8rbt0fp","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/5","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00173,"epssPercentile":0.06096,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:42.167Z","addedAt":"2026-10-08T10:39:34.958Z","updatedAt":"2026-10-08T18:39:31.166Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71895","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71895","note":"authoritative record"}]},{"id":"20320e22-60e6-4e42-8673-3157e547967f","slug":"cve-2026-86827","externalId":"CVE-2026-86827","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86827 — The BackWPup  WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from …","description":"The BackWPup  WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.","cveId":"CVE-2026-86827","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/c7785a5b-f580-416f-a23d-58c28c717b60/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00151,"epssPercentile":0.03752,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:44.987Z","addedAt":"2026-10-08T06:39:29.732Z","updatedAt":"2026-10-08T21:05:47.222Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86827","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86827","note":"authoritative record"}]},{"id":"24801f15-9f2e-4d4f-a9af-c6ebbb5a5e70","slug":"cve-2026-87669","externalId":"CVE-2026-87669","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87669 — A missing authorization check in Brocade Fabric OS versions before 10.0.1 REST API interface of affected platform releases allows an authenticated …","description":"A missing authorization check in Brocade Fabric OS versions before 10.0.1 REST API interface of affected platform releases allows an authenticated user, regardless of their assigned role or administrative scope, to retrieve complete Monitoring and Alerting Policy Suite (MAPS) violation data across all logical switches. An attacker with low-privilege API access can leverage this endpoint to dump chassis-wide system health metrics, port performance violations, and configuration data without appropriate privileges.","cveId":"CVE-2026-87669","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39139","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00139,"epssPercentile":0.0282,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:36.237Z","addedAt":"2026-10-08T04:39:32.905Z","updatedAt":"2026-10-08T21:05:45.544Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87669","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87669","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":2808,"totalPages":141,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:55:24.797Z","durationMs":38,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-862"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}