{"success":true,"data":{"threats":[{"id":"39e0d9e5-8b84-4dc1-a45d-6ac19008c7c1","slug":"cve-2026-84275","externalId":"CVE-2026-84275","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84275 — IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality.","description":"IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.","cveId":"CVE-2026-84275","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:38.077Z","addedAt":"2026-10-08T21:05:53.603Z","updatedAt":"2026-10-08T21:05:53.603Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84275","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84275","note":"authoritative record"}]},{"id":"90e9b43c-b403-49f6-a694-e50222e94006","slug":"cve-2026-84274","externalId":"CVE-2026-84274","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84274 — IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability.","description":"IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability. During SECRET and API_KEY rotation processing, sensitive credential material is logged at INFO level by the edge-controller/edge-manager components. An authenticated attacker with access to the relevant application or container logs could obtain these credentials and use them to impersonate services or gain unauthorized access to the Guardium control plane.","cveId":"CVE-2026-84274","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-200"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288627","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.927Z","addedAt":"2026-10-08T21:05:53.590Z","updatedAt":"2026-10-08T21:05:53.590Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84274","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84274","note":"authoritative record"}]},{"id":"ea338b45-cb6d-4411-93e9-59432a3a11fe","slug":"cve-2026-84272","externalId":"CVE-2026-84272","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84272 — IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component.","description":"IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.","cveId":"CVE-2026-84272","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-306"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288832","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.753Z","addedAt":"2026-10-08T21:05:53.576Z","updatedAt":"2026-10-08T21:05:53.576Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84272","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84272","note":"authoritative record"}]},{"id":"bf0728c8-348b-4e5d-98d8-32a7b1942e85","slug":"cve-2026-84271","externalId":"CVE-2026-84271","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84271 — IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer.","description":"IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.","cveId":"CVE-2026-84271","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.610Z","addedAt":"2026-10-08T21:05:53.557Z","updatedAt":"2026-10-08T21:05:53.557Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84271","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84271","note":"authoritative record"}]},{"id":"3e4bcc36-08ac-4e7e-8fdd-a07fae3a7636","slug":"cve-2026-84250","externalId":"CVE-2026-84250","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84250 — IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component.","description":"IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.","cveId":"CVE-2026-84250","cvssScore":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.460Z","addedAt":"2026-10-08T21:05:53.540Z","updatedAt":"2026-10-08T21:05:53.540Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84250","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84250","note":"authoritative record"}]},{"id":"5cb82945-9f1a-49b7-aa82-d67c549a60ba","slug":"cve-2026-84245","externalId":"CVE-2026-84245","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84245 — IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component.","description":"IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.","cveId":"CVE-2026-84245","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.313Z","addedAt":"2026-10-08T21:05:53.514Z","updatedAt":"2026-10-08T21:05:53.514Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84245","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84245","note":"authoritative record"}]},{"id":"651ba35b-e990-4680-992b-2edfaf179870","slug":"cve-2026-84244","externalId":"CVE-2026-84244","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84244 — IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search resu…","description":"IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.","cveId":"CVE-2026-84244","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.160Z","addedAt":"2026-10-08T21:05:53.504Z","updatedAt":"2026-10-08T21:05:53.504Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84244","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84244","note":"authoritative record"}]},{"id":"19c01176-9114-4dc9-9f2b-d7ceefe4c896","slug":"cve-2026-82344","externalId":"CVE-2026-82344","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82344 — IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality.","description":"IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.","cveId":"CVE-2026-82344","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291670","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.020Z","addedAt":"2026-10-08T21:05:53.488Z","updatedAt":"2026-10-08T21:05:53.488Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82344","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82344","note":"authoritative record"}]},{"id":"0de67ead-c6ad-4260-85ce-cf214c9b617d","slug":"cve-2026-82335","externalId":"CVE-2026-82335","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82335 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser.","description":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution.","cveId":"CVE-2026-82335","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-119"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291674","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:36.873Z","addedAt":"2026-10-08T21:05:53.452Z","updatedAt":"2026-10-08T21:05:53.452Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82335","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82335","note":"authoritative record"}]},{"id":"d7b5b18f-0012-4a65-a47e-c99879742767","slug":"cve-2026-82334","externalId":"CVE-2026-82334","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82334 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser.","description":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service.","cveId":"CVE-2026-82334","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291670","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:36.737Z","addedAt":"2026-10-08T21:05:53.407Z","updatedAt":"2026-10-08T21:05:53.407Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82334","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82334","note":"authoritative record"}]},{"id":"b4beefc5-fe47-4c59-bd73-0c9decd67cc5","slug":"cve-2026-107707","externalId":"CVE-2026-107707","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…","description":"Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM.","cveId":"CVE-2026-107707","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.quarkslab.com/milking-the-last-drop-of-intego-time-for-windows-to-get-its-lpe.html","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.intego.com/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/intego-antivirus-through-3.0.0.1-local-privilege-escalation-via-optimization-module-junction","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.690Z","addedAt":"2026-10-08T21:05:53.368Z","updatedAt":"2026-10-08T21:05:53.368Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107707","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107707","note":"authoritative record"}]},{"id":"a01a5b11-d109-4914-9845-206120efeaaf","slug":"cve-2026-107706","externalId":"CVE-2026-107706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…","description":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.","cveId":"CVE-2026-107706","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Dolibarr/dolibarr","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.503Z","addedAt":"2026-10-08T21:05:53.311Z","updatedAt":"2026-10-08T21:05:53.311Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107706","note":"authoritative record"}]},{"id":"d0ce1ab4-e33c-471d-a940-5d0cff40dda8","slug":"cve-2026-107705","externalId":"CVE-2026-107705","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107705 — Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to…","description":"Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.","cveId":"CVE-2026-107705","cvssScore":8.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-121"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.freedesktop.org/poppler/poppler","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/blob/poppler-26.10.0/poppler/Decrypt.cc#L1767","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2398","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1814","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/poppler-0.42.0-through-26.10.0-stack-buffer-overflow-via-decrypt-revision6hash","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.300Z","addedAt":"2026-10-08T21:05:53.273Z","updatedAt":"2026-10-08T21:05:53.273Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107705","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107705","note":"authoritative record"}]},{"id":"4b6ca1c2-6516-4bc7-aca2-8822b06b82ad","slug":"cve-2026-107608","externalId":"CVE-2026-107608","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…","description":"Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset.\n\n\n\nTo remediate this issue, users should upgrade to version 2.267.0 or later.","cveId":"CVE-2026-107608","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-131-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-cdk/releases/tag/v2.267.0","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.967Z","addedAt":"2026-10-08T21:05:53.252Z","updatedAt":"2026-10-08T21:05:53.252Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107608","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107608","note":"authoritative record"}]},{"id":"169c981d-6fa7-431c-aeb0-4680532b6441","slug":"cve-2026-107396","externalId":"CVE-2026-107396","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107396 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107396","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-692"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7619","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.417Z","addedAt":"2026-10-08T21:05:53.210Z","updatedAt":"2026-10-08T21:05:53.210Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107396","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107396","note":"authoritative record"}]},{"id":"e7710434-db62-4435-9d72-5db3a0047c7d","slug":"cve-2026-107395","externalId":"CVE-2026-107395","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session without access to that session, as long as the containing event is accessible. The missing access check can disclose session metadata such as the title, description, and conveners. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107395","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-862"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/524e8e93eadcd8484905b1147020a35f5dce6038","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-6p4f-j8j6-463q","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.250Z","addedAt":"2026-10-08T21:05:53.094Z","updatedAt":"2026-10-08T21:05:53.094Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107395","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107395","note":"authoritative record"}]},{"id":"bd24b01c-cba8-4942-a651-8383c234cbaf","slug":"cve-2026-107394","externalId":"CVE-2026-107394","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107394 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.","description":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, the previous fix for CVE-2026-25738 did not cover an edge case, allowing an event organizer to submit a crafted URL that points to a prohibited local target but is accepted as valid by Indico. The organizer can read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13.","cveId":"CVE-2026-107394","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/indico/indico/commit/44540e70ab4e20a12f14ddba5218a33749a86736","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/pull/7573","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/indico/indico/security/advisories/GHSA-2v95-h47v-g4x9","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.073Z","addedAt":"2026-10-08T21:05:53.032Z","updatedAt":"2026-10-08T21:05:53.032Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107394","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107394","note":"authoritative record"}]},{"id":"fd0125cc-dbd5-4eef-be9a-bf7ee7eb0d3d","slug":"cve-2026-107393","externalId":"CVE-2026-107393","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107393 — FreeScout is a self-hosted help desk and shared mailbox.","description":"FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.","cveId":"CVE-2026-107393","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79","CWE-116"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.893Z","addedAt":"2026-10-08T21:05:53.011Z","updatedAt":"2026-10-08T21:05:53.011Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107393","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107393","note":"authoritative record"}]},{"id":"57eb179a-6e66-40a5-add9-291967e26a1e","slug":"cve-2026-107392","externalId":"CVE-2026-107392","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.","cveId":"CVE-2026-107392","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.15.0"],"cwes":["CWE-248","CWE-400"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-8j4c-6x6g-rq3j","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/e7fc27a96e789d41ece41fdac590fc7618274a41","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2700","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.15.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-8j4c-6x6g-rq3j","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-8j4c-6x6g-rq3j","type":"advisory","title":"OSV GHSA-8j4c-6x6g-rq3j"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.707Z","addedAt":"2026-10-08T21:05:52.984Z","updatedAt":"2026-10-08T21:08:30.817Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107392","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107392","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8J4C-6X6G-RQ3J"}]},{"id":"058f0d42-6c83-46b2-ac64-ab25a6feb0d3","slug":"cve-2026-107391","externalId":"CVE-2026-107391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107391","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-f94x-6692-553q","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/90a7d52c69e921a0b019592d887acd97b1c8b8a5","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2734","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-f94x-6692-553q","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f94x-6692-553q","type":"advisory","title":"OSV GHSA-f94x-6692-553q"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.530Z","addedAt":"2026-10-08T21:05:52.968Z","updatedAt":"2026-10-08T21:08:30.734Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107391","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F94X-6692-553Q"}]}],"pagination":{"page":1,"limit":20,"total":69502,"totalPages":3476,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T22:31:08.463Z","durationMs":244,"filters":{"search":null,"severity":[],"type":["vulnerability"],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}